Compliance

We're a small, early-stage team building infrastructure we're proud of. Here's an honest picture of where we are on compliance today — what's shipped, what's in progress, and what's on the roadmap.

Honest startup disclosure

We are not yet SOC 2 certified, do not yet hold a HIPAA BAA program, and have not completed formal GDPR/CCPA assessments with a third-party auditor. We are working through these. This page reflects current reality, not aspirations. If you need specific certifications before signing up, email us — we'll tell you where we actually are.

SOC2
SOC 2 Type II
In Progress
GDPR
GDPR
Practices In Place
HIPAA
HIPAA / BAA
On Roadmap

What's shipped today

These controls exist today and are live

Encryption at rest (AES-256 via AWS KMS on all EBS and S3). Encryption in transit (TLS 1.3 enforced, minimum TLS 1.2). Per-sandbox process isolation — each agent runs in its own container with separate filesystem, network namespace, and process tree. Audit logs on all API calls, container starts/stops, and admin actions. Role-based access control. Passwords hashed (bcrypt). Secrets stored separately from application data.

These aren't things we're working toward — they're running in production now. If you need to verify any of them technically, email security@ab0t.com and we'll walk you through it.

SOC 2 Type II

We are currently working through the controls and documentation required for a SOC 2 Type II audit. We have not yet completed the audit. We do not yet have a report to share.

What we are doing: documenting all security controls, implementing a formal change management process, setting up continuous monitoring, and working with an auditor. This takes time done properly — we'd rather do it right than rush a paper exercise.

If your procurement process requires a SOC 2 report before signing, we're not the right fit today. If you're comfortable with a controls summary and a direct conversation with our team, email security@ab0t.com.

Privacy: GDPR and CCPA

We respect data subject rights and handle personal data responsibly. We do not sell personal data. These are commitments we make operationally today, even before formal third-party assessment:

Data subject rights we honor now

What we don't yet have

If you need a DPA to sign a contract, contact privacy@ab0t.com — we can share our draft and discuss timeline.

HIPAA

We do not currently offer a Business Associate Agreement (BAA). If you need to run workloads involving Protected Health Information (PHI), we are not yet the right infrastructure choice.

We are aware of the requirements and have the technical foundations in place (encryption at rest and in transit, audit logging, access controls). Getting to a proper HIPAA BAA program involves legal review, updated policies, and a signed agreement structure — that's on our roadmap but not something we'll rush.

If HIPAA compliance is a hard requirement for you today, email security@ab0t.com — we'll tell you honestly whether we can help and on what timeline.

Data Residency

Today, all infrastructure runs in AWS US-West (us-west-2). We do not currently offer data residency controls or region selection.

If your data must stay within the EU or another specific region, we cannot currently guarantee that. EU region support is on our roadmap. Contact sales@ab0t.com if this is a blocker and we'll discuss what's realistic.

Security Questionnaires

We're happy to complete your security questionnaire. We'll answer honestly — including "not yet" where that's the true answer. Send it to security@ab0t.com. We typically turn these around within 5 business days.

We also support authorized penetration tests for enterprise customers. Contact us to arrange scope and scheduling before testing.

Subprocessors

We use the following third-party providers to deliver the service:

Subprocessor Purpose Location
Amazon Web Services Infrastructure (compute, storage, networking) US-East-1 (Virginia)
Stripe Payment processing United States
Anthropic / OpenAI Underlying model API (used only when you use our AI features) United States

We'll update this list when we add new subprocessors. To get notified, email privacy@ab0t.com.

Roadmap

Item Status Notes
SOC 2 Type II audit In progress Controls documentation underway. No committed date.
GDPR Data Processing Agreement (DPA) In progress Draft exists. Legal review in progress.
HIPAA BAA program Planned After SOC 2. No committed date.
EU data residency (Frankfurt) Planned On infrastructure roadmap. No committed date.
Vulnerability disclosure program In progress Email security@ab0t.com for responsible disclosure in the meantime.

Contact

Last updated: May 2026. We update this page when our status materially changes.