AnterisLab
Resources · Compliance

Compliance & trust

The frameworks we are certified or aligned against, where your data lives, who processes it, and how to obtain an audit report.

Frameworks

FrameworkStatusNotes
SOC 2 Type II Report in progressObservation window closed; report expected Q4 2026. Type I report available under NDA.
ISO/IEC 27001 Roadmap 2027ISMS controls documented; certification audit planned after SOC 2.
UK GDPR & EU GDPR CompliantCompliant. DPA available, data stored in the EU (Ireland), records of processing maintained.
EU AI Act AlignedAudit trail and human-oversight controls map to the transparency and logging obligations for high-risk systems.
HIPAA AvailableBAA offered on Enterprise plans; PHI stays within the EU (Ireland) database region.
PCI DSS Not applicableAnterisLab does not store, process or transmit cardholder data. Payment actions are decisions, not charges.

Controller: SAASDEVSOLUTIONS LTD · Registered in England and Wales, Company Number 17362476 · Registered office: 167-169 Great Portland Street, 5th Floor, London, United Kingdom · Registered with the ICO.

Data & residency

  • Customer data is stored in the European Union — Ireland. The application and edge delivery are deployed on Vercel in the United States; the database and its backups remain in the EU (Ireland). Self-hosting is available on Enterprise.
  • Because requests are served from the United States while data rests in the EU (Ireland), international transfers rely on the UK International Data Transfer Addendum and the European Commission Standard Contractual Clauses — see Privacy Policy — International transfers.
  • Decision context is retained for 30 days by default and configurable from 7 to 365 days. Audit records are retained for the contractual term.
  • Data in transit is protected with TLS 1.2+; data at rest is encrypted with AES-256 and per-workspace keys.
  • Sub-processor changes are announced at least 30 days in advance; customers may object and terminate without penalty.

Sub-processors

Sub-processorPurposeLocationDPA
SupabaseManaged Postgres, authentication storageEU (Ireland)supabase.com/legal/dpa
VercelApplication hosting, edge delivery and serverless API runtimeUnited States (deployment)vercel.com/legal/dpa
StripeSubscription billingUK / EUstripe.com/legal/dpa
ResendTransactional email delivery (password reset, email change, signup confirmation)United States / EUresend.com/legal/dpa
Zoho MailBusiness mailbox for support, security and compliance correspondenceEU / United Stateszoho.com/privacy/dpa.html
GitHubSource code hosting, CI/CD, dependency updates for the SDK and siteUnited Statesgithub.com/customer-terms
GoatCounterCookie-free, anonymous site analyticsEUgoatcounter.com/help/privacy

Audit requests

Security questionnaires, penetration-test summaries, DPAs and SOC reports are available to customers and prospects under NDA. Write to compliance@anterislab.com.

Public DPAs from our sub-processors are linked in the table above. If you need a countersigned DPA with SAASDEVSOLUTIONS LTD, write to legal@anterislab.com.