— SECURITY · 06 OF 07 · ROADMAP & STATUS

Compliance, honestly.
What’s done. What’s in audit. What’s queued.

Some companies plaster certifications they don’t actually hold. We’d rather show the real status, including in-flight audits and gaps. If we don’t have it, we say so. If we’re working on it, we say so. If we’re not pursuing it, we explain why.

STATUS DATE2026-05-10
NEXT AUDITSOC 2 Type I · Q3 2026
LIVE STANDARDS3
IN AUDIT2

01Status matrix.

Standard
What it covers
Status
Target
GDPR
EU privacy / data protection regulation
Compliant
Live
DPDP Act 2023
India’s personal data protection law
Compliant
Live
UK GDPR
UK privacy regulation post-Brexit
Compliant
Live
SOC 2 Type I
Trust Services Criteria · point-in-time
In audit
Q3 2026
SOC 2 Type II
Trust Services Criteria · 6-month operational
Roadmap
Q1 2027
ISO 27001:2022
Information security management
In audit
Q4 2026
ISO 27701
Privacy information management
Roadmap
Q2 2027
HIPAA
US healthcare data privacy
Roadmap
Q3 2027 · on demand
PCI DSS
Payment card data
Not applicable
n/a
FedRAMP
US federal cloud
Not pursuing
n/a (out of scope)

02Why this order.

Privacy regulations (GDPR, DPDP, UK GDPR) come first because they apply by default to every customer with EU / India / UK data subjects. Aligning to them is non-optional from day one.

SOC 2 Type I + ISO 27001 come next because enterprise procurement teams treat them as table stakes. SOC 2 Type II follows naturally once we have 6 months of operational evidence to point at.

HIPAA is on the roadmap but only relevant when we onboard a healthcare customer; we don’t pursue it speculatively. PCI DSS is not applicable because we don’t process card data ourselves — Stripe / Razorpay handle that, and they hold the relevant certifications.

03What “compliant” means here.

For privacy regulations (GDPR, DPDP, UK GDPR), “compliant” means we have implemented the controls the regulation requires (lawful basis, data subject rights, breach notification, etc.) and our DPA aligns. There is no certification body for these — compliance is self-attested and audit-defensible.

For SOC 2 / ISO 27001, “in audit” means an external auditor (named on request under NDA) is currently running fieldwork. “Compliant” will only be claimed after the report is issued.

04Customer obligations.

Compliance is shared. We provide the platform; you operate within it lawfully. Specifically:

  • You determine the lawful basis for processing your end-users’ data via Cyborgs (consent, legitimate interest, contract, etc.).
  • You handle data-subject requests (access, erasure, portability) addressed to you. We support you within 7 days for any data we hold on your behalf.
  • You configure scope grants within the bounds appropriate for your jurisdiction and your end-users’ expectations.
  • You comply with the AUP. Mis-use of Cyborgs to process data unlawfully is a customer issue we cannot prevent at the platform layer.

05Reports + access.

  • SOC 2 / ISO reports · available under a one-page mutual NDA, once issued. Email trust@anilcyborg.com.
  • Pen-test summary · annual external test executive summary available under NDA. Full report: enterprise customers only.
  • Security questionnaires · we have pre-filled CAIQ + SIG Lite responses. Reply within 1 business day on standard formats.
  • Customer audits · per the DPA, you can audit our processing once per year with 30-day notice. Many customers accept SOC 2 Type II in lieu.