Skip to main content

Compliance Operations

  • SOC 2 readiness with documented controls and audits
  • GDPR: data residency, DSAR, right-to-be-forgotten workflows
  • Vendor due diligence artifacts on request
  • Incident response with time-bound SLAs

Data Residency and Exports

  • Data hosted with Supabase; exports on request
  • Residency options via regional projects
  • Immutable audit logs for access

DSAR Workflow

  1. Authenticate requestor identity
  2. Export user data package
  3. Apply deletion within SLA, update audit log

Incident Response

  • Severity matrix with response times
  • Postmortem template and action tracking
  • Customer communication channels
See also: Security, Data Governance.