> ## Documentation Index
> Fetch the complete documentation index at: https://docs.chromaflow.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Compliance

> Operational practices for SOC2 readiness, GDPR, incident response, and enterprise procurement.

# Compliance Operations

* SOC 2 readiness with documented controls and audits
* GDPR: data residency, DSAR, right-to-be-forgotten workflows
* Vendor due diligence artifacts on request
* Incident response with time-bound SLAs

## Data Residency and Exports

* Data hosted with Supabase; exports on request
* Residency options via regional projects
* Immutable audit logs for access

## DSAR Workflow

1. Authenticate requestor identity
2. Export user data package
3. Apply deletion within SLA, update audit log

## Incident Response

* Severity matrix with response times
* Postmortem template and action tracking
* Customer communication channels

See also: [Security](security), [Data Governance](data-governance).
