— SECURITY · 06 OF 07 · ROADMAP & STATUS
Compliance, honestly.
What’s done. What’s in audit. What’s queued.
Some companies plaster certifications they don’t actually hold. We’d rather show the real status, including in-flight audits and gaps. If we don’t have it, we say so. If we’re working on it, we say so. If we’re not pursuing it, we explain why.
02Why this order.
Privacy regulations (GDPR, DPDP, UK GDPR) come first because they apply by default to every customer with EU / India / UK data subjects. Aligning to them is non-optional from day one.
SOC 2 Type I + ISO 27001 come next because enterprise procurement teams treat them as table stakes. SOC 2 Type II follows naturally once we have 6 months of operational evidence to point at.
HIPAA is on the roadmap but only relevant when we onboard a healthcare customer; we don’t pursue it speculatively. PCI DSS is not applicable because we don’t process card data ourselves — Stripe / Razorpay handle that, and they hold the relevant certifications.
03What “compliant” means here.
For privacy regulations (GDPR, DPDP, UK GDPR), “compliant” means we have implemented the controls the regulation requires (lawful basis, data subject rights, breach notification, etc.) and our DPA aligns. There is no certification body for these — compliance is self-attested and audit-defensible.
For SOC 2 / ISO 27001, “in audit” means an external auditor (named on request under NDA) is currently running fieldwork. “Compliant” will only be claimed after the report is issued.
04Customer obligations.
Compliance is shared. We provide the platform; you operate within it lawfully. Specifically:
- You determine the lawful basis for processing your end-users’ data via Cyborgs (consent, legitimate interest, contract, etc.).
- You handle data-subject requests (access, erasure, portability) addressed to you. We support you within 7 days for any data we hold on your behalf.
- You configure scope grants within the bounds appropriate for your jurisdiction and your end-users’ expectations.
- You comply with the AUP. Mis-use of Cyborgs to process data unlawfully is a customer issue we cannot prevent at the platform layer.
05Reports + access.
- SOC 2 / ISO reports · available under a one-page mutual NDA, once issued. Email trust@anilcyborg.com.
- Pen-test summary · annual external test executive summary available under NDA. Full report: enterprise customers only.
- Security questionnaires · we have pre-filled CAIQ + SIG Lite responses. Reply within 1 business day on standard formats.
- Customer audits · per the DPA, you can audit our processing once per year with 30-day notice. Many customers accept SOC 2 Type II in lieu.