Security & Compliance Roadmap
Current certification status, what exists today, and the sequenced path to SOC 2 Type I.
Current State
No certifications held today. No SOC 2 (Type I or II), no ISO 27001, no external penetration test performed, no external auditor engaged.
What Exists Today
- →A self-authored SOC 2 readiness assessment mapped to the Trust Services Criteria, with gaps explicitly marked
- →Nine adopted security policies (adopted 24 July 2026), plus a SOC 2 program plan and a vendor register
- →Append-only security-event and audit-event streams
- →Access-review evidence export
- →Database-enforced row-level security across the schema
- →AES-256-GCM credential encryption
- →Dual-control approvals
Milestones
July 2027.
July 2027, alongside SOC 2 preparation.
Near-term roadmap item; no date committed.
Standing remediation item — the production database tier currently includes no scheduled backups (verified 24 July 2026). No date committed.
Done — the nine-policy pack was adopted on 24 July 2026.
Not yet bound; no date committed.
Incident-response formalisation is tied to SOC 2 preparation — closing the gap flagged in the readiness assessment.
Alongside SOC 2 preparation; target July 2027.
Framing
Certification work is deliberately sequenced after first design-partner commitments; the readiness map exists so the gap between today and Type I is known and bounded.