Compliance programme

The policies and controls Depozza operates so a SOC 2, ISO 27001 or GDPR review can be evidenced.

Version 1.0 · Effective 2026-08-11

This programme documents what we actually do — access control, retention, incident response, change management, continuity, risk and suppliers. It is written for auditors, insurers and business customers who need evidence rather than marketing.

Policy documents

Control overview

Mapped to SOC 2 Trust Services Criteria, ISO/IEC 27001:2022 Annex A and the GDPR.

  • Row-level security on every table, plus column-level revokes on sensitive fields

    CC6 · A.5.15

    In place
  • Multi-factor authentication and leaked-password checking on accounts

    CC6.1

    In place
  • Append-only audit log of administrative and sensitive actions

    CC7.2 · A.8.15

    In place
  • Versioned database migrations and automated checks before release

    CC8.1

    In place
  • Encrypted automated backups with point-in-time recovery, stored in the EU

    A1.2 · A.8.13

    In place
  • Self-service data export and account deletion in Settings

    GDPR 15/17/20

    In place
  • Documented incident response with 72-hour regulator notification

    GDPR 33 · CC7.4

    In place
  • Published subprocessor list with EU hosting or standard contractual clauses

    A.5.19

    In place
  • Independent external penetration test

    CC4.1

    Planned
  • Third-party audit and certification (not yet started)

    SOC 2 / ISO 27001

    Planned

No certification claimed

Depozza SAS is not SOC 2 attested and not ISO 27001 certified, and HIPAA does not apply because we process no health data. These documents are our own commitments; controls marked “planned” are not yet in place.