Trust & security

Compliance roadmap — SOC 2 Type I + ISO 27001

We're committed to earning enterprise trust. SOC 2 Type I audit kicks off Q1 2026; ISO 27001 certification targeted for Q3 2026.

Compliance frameworks

6 frameworks · audited status

Roadmap

SOC 2 Type I

Audit kicks off Q1 2026. Vanta continuous monitoring + Type I report expected mid-Q1.

Auditor
Vanta (pending)
Scope
Security, Availability, Confidentiality
Planned

SOC 2 Type II

Twelve-month observation window post Type I. Targeted for Q3 2026.

Auditor
Vanta (pending)
Scope
12-month observation period post-Type I
Roadmap

ISO 27001

Targeted for Q3 2026. Full Annex A controls rollout beginning Q1 2026.

Auditor
EY or BSI (pending RFP)
Scope
Annex A — 14 domains, 35 controls
Compliant today

GDPR

Compliant today. EU data residency optional on Enterprise tier (Dublin / Frankfurt regions).

Auditor
Self-attested
Scope
Right to erasure, data export, consent log
Compliant today

CCPA

Compliant today. Consumer rights endpoint exposes deletion and access requests programmatically.

Auditor
Self-attested
Scope
"Do Not Sell My Info" opt-out · consumer rights API
Planned

HIPAA

PHI handling as opt-in feature. BAA executed per-customer. Encryption at rest + in transit enforced.

Auditor
BAA available on request
Scope
Opt-in feature (Enterprise tier)
ISO 27001 controls

Annex A controls preview (ISO 27001)

14 domains · 35 controls · current implementation status

A.5
Information Security Policies
Published in /docs/security — versioned & public
A.6
Organization of Information Security
AliceLabs LLC founding charter + RACI matrix live
A.7
Human Resource Security
Pre-employment screening + NDA on file for all engineers
A.8
Asset Management
Asset registry in GitHub + cloud inventory in Terraform
A.9
Access Control
RBAC + SSO enforced; least-privilege by default
A.10
Cryptography
AES-256 at rest · TLS 1.3 in transit · KMS-managed keys
A.11
Physical and Environmental Security
Cloudflare + AWS data centers (SOC 2 inherited)
A.12
Operations Security
CI/CD pipeline with signed commits + dependency scanning
A.13
Communications Security
MTLS between services · WAF on edge · rate-limit by default
A.14
System Acquisition, Development and Maintenance
Secure SDLC · threat modeling per feature · SAST + DAST
A.15
Supplier Relationships
Vendor risk assessment on file for every integration
A.16
Information Security Incident Management
24-hour disclosure SLA · security@alicelabs.site monitored
A.17
Aspects of Business Continuity Management
Multi-region failover · RPO 5min · RTO 30min
A.18
Compliance
Legal review per release · privacy by design · audit log immutable
Procurement

Need our compliance docs for procurement?

Share your email and we'll send the requested docs within 24 hours. No sales calls.

Stored locally — no data sent to any server.
Other trust signals

Things we already do well today — not future promises.

Self-hosted Docker image available

Ship under AL-1.0 license. Run enrichment fully on-prem — no egress.

No third-party data egress

Enterprise tier pins all outbound calls to approved registries only.

Open-source enricher engine

Audit-able source on GitHub. Every worker is inspectable.

Pricing transparency

All 5 tiers published online. No sales calls required to start.

Ready to start?

Start with 100 records free, no credit card. Enterprise tier available with 99.9% SLA and on-prem Docker.