| ISO 27001 / SOC 2 | Not certified; stack is prepared for formal audit | Audit scope, auditor, target timeline |
| DPA | Standard DPA access and coverage are documented in Data Processing Addendum | Signed DPA, controller/processor roles, subprocessor terms |
| Subprocessors | Current provider list is documented in Compliance & GDPR | Provider locations, transfer mechanisms, notice period |
| Data residency | Primary hosting is AWS Frankfurt by default | Contract wording for requested region, Availability Zone coverage, custom domain, and CDN edge/POP requirements |
| Private asset storage | Enterprise private assets use private storage and signed URLs | Bucket policy, public-access-block policy, signed URL TTL |
| Storage access logs | Private asset storage events are logged separately | Log destination, lifecycle policy, retention evidence |
| Application audit logs | Security-relevant events are retained for 365 days | Audit event schema, export sample, lifecycle policy |
| Backup retention | MongoDB Atlas backup retention target is 24 hours | Backup policy, restore test evidence |
| RTO / RPO | Recovery targets are contract-specific | RTO, RPO, escalation owner |
| SLA and support | Support commitments are contract-specific | SLA, support hours, severity definitions, escalation path |
| Incident response | 72-hour breach notification commitment is included in enterprise DPA terms | Incident runbook summary, notification timeline |
| Admin access | Administrative actions are audit-logged and privileged access is reviewed | Access review evidence, privileged role list |
| AI processing | AI data flow is documented by feature | Provider terms, opt-in feature list, data categories, training/retention position |