Compliance
Regulatory compliance, certifications, and security standards
Compliance
Current Status
SoxAI is in the process of obtaining formal certifications. The following reflects our current compliance posture.
| Standard | Status | Notes |
|---|---|---|
| OWASP Top 10 | Implemented | Full mitigation of all Top 10 categories |
| SOC 2 Type II | In Progress | Target: Q3 2026 |
| ISO 27001 | Planned | Target: Q4 2026 |
| GDPR | Compliant | EU data processing agreements available |
| CCPA | Compliant | California consumer rights honored |
| HIPAA | Not certified | Contact us for Enterprise discussions |
OWASP Top 10 Coverage
| OWASP Category | SoxAI Implementation |
|---|---|
| A01 Broken Access Control | Tenant isolation via tenant_id in all queries + PG Row-Level Security |
| A02 Cryptographic Failures | AES-256-GCM for secrets, Argon2id for passwords, TLS 1.2+ enforced |
| A03 Injection | All DB queries via sqlc parameterized queries, no string concatenation |
| A04 Insecure Design | Pre-consumption billing prevents overspend, scope-limited tokens |
| A05 Security Misconfiguration | Secrets via Ansible Vault, internal services not exposed to internet |
| A06 Vulnerable Components | govulncheck and trivy scan every CI build |
| A07 Authentication Failures | Brute-force lockout, JWT rotation, WebAuthn MFA |
| A08 Software and Data Integrity | Signed Docker images, dependency checksums |
| A09 Logging and Monitoring | Audit log for all auth events, OTel traces for all requests |
| A10 SSRF | Upstream URL validated against allowlist before every request |
GDPR
SoxAI processes personal data as both a data controller (for account data) and data processor (when your prompts are forwarded to AI providers).
For EU customers:
- Data Processing Agreements (DPA) are available on request
- The right to access, rectify, and erase personal data is supported via the Console
- Data is processed on the basis of contract performance and legitimate interests
Contact [email protected] to request a DPA.
Security Audits
SoxAI conducts internal security reviews before each major release. External penetration testing is planned for Q2 2026.
Audit reports are available to Enterprise customers under NDA.
Responsible Disclosure
We run a responsible disclosure program. If you discover a security vulnerability:
- Email [email protected] with details
- We acknowledge within 24 hours
- We provide a fix timeline within 72 hours for critical issues
- We credit researchers in our security changelog (with permission)
We do not take legal action against researchers acting in good faith.
Access Control Policy
SoxAI employees:
- Access production systems only through a bastion host with MFA
- Follow least-privilege principles (read-only access by default)
- Cannot access prompt content — only metadata and token counts
- Are subject to background checks
Production database credentials are managed via Ansible Vault and rotated quarterly.
Incident Response
In the event of a security incident:
- We contain and assess the incident within 4 hours
- We notify affected customers within 72 hours (as required by GDPR)
- We publish a post-mortem within 7 days
For critical infrastructure incidents, subscribe to status updates at status.soxai.io.