Trust Center
Compliance & Regulatory Posture
Last Updated: June 2026
Overview
This page states what RequirementsHub's compliance posture actually is — not what sounds impressive. Procurement teams, security reviewers, and customers should be able to make informed decisions based on facts, not aspirations. Where a framework is "in progress" or "not supported," we say so plainly.
SOC 2
| Item | Status |
|---|---|
| Type II report | Not yet issued |
| Audit firm | To be selected |
| Trust Service Criteria in scope | Security, Availability, Confidentiality (planned) |
| Target timeline | Audit initiation planned within 6 months; Type I report targeted within 12 months; Type II observation window to follow |
| Compensating evidence available today | Subprocessor SOC 2 reports (Cloudflare, Supabase, Stripe), this Trust Center, our Security and Data Handling pages, DPA |
| Bridge letters | Not applicable until first report is issued |
GDPR
| Item | Status |
|---|---|
| Role | Data Processor for customer-uploaded content; Data Controller for our own account and billing data |
| Lawful basis for processing | Contract (Article 6(1)(b)) for service delivery; Legitimate interest for security and product reliability |
| DPA | Published at requirementshub.ai/trust/dpa; auto-incorporated into customer agreement on Pro and Enterprise plans |
| Standard Contractual Clauses | Module 2 (Controller-to-Processor) included in the DPA Annex for EEA / UK / Swiss transfers |
| Data subject rights | Self-service export and deletion via /account/data; manual requests via privacy@requirementshub.ai |
| Breach notification | 72 hours from confirmation (see Incident Response) |
| EU representative | Not currently appointed; available on request for Enterprise customers |
UK GDPR
The UK GDPR mirrors the EU GDPR. RequirementsHub treats UK personal data on the same basis as EEA personal data and includes the UK International Data Transfer Addendum (IDTA) in the DPA for transfers from the UK.
HIPAA
| Item | Status |
|---|---|
| HIPAA-covered service | No |
| Business Associate Agreement (BAA) | Not offered |
| PHI permitted on the platform | No — see Acceptable Use Policy |
RequirementsHub is not a HIPAA-covered service and does not sign Business Associate Agreements. Protected Health Information must not be uploaded to the platform. Healthcare teams using RequirementsHub for requirements analysis should ensure source documents are scrubbed of PHI before upload, or use synthetic / representative data.
CCPA / CPRA
| Item | Status |
|---|---|
| Role under CCPA | Service Provider to business customers; Business for our own account and billing data |
| Sale or sharing of personal information | We do not sell or share personal information for cross-context behavioral advertising |
| Consumer rights (access, delete, correct, portability) | Honored via /account/data self-service and privacy@requirementshub.ai |
| Sensitive personal information | Limited processing; see Privacy Policy |
PCI DSS
| Item | Status |
|---|---|
| Cardholder data stored, transmitted, or processed by RequirementsHub | None — payment processing is fully outsourced to Stripe |
| Stripe PCI DSS level | Level 1 (highest) |
| Our PCI scope | SAQ A eligible (no cardholder data touches our environment) |
Export Controls
| Item | Status |
|---|---|
| Service classification | Commercial SaaS; no encryption product export classification claimed |
| Sanctioned jurisdictions | We do not knowingly provide service to users or organizations in OFAC-sanctioned jurisdictions |
| Export-controlled technical data | Prohibited from upload — see Acceptable Use Policy |
Roadmap
| Milestone | Target |
|---|---|
| SOC 2 audit firm selected | Within 3 months |
| SOC 2 readiness assessment complete | Within 6 months |
| First penetration test (third-party) | Concurrent with SOC 2 readiness |
| SOC 2 Type I report issued | Within 12 months |
| SOC 2 Type II observation window complete | Within 18–24 months |
| MFA generally available for customer accounts | Within 6 months |
| Public status page | Within 3 months |
| Formal vulnerability disclosure / bounty program | After SOC 2 Type I |
Questions
Contact security@requirementshub.ai for security and audit inquiries, or legal@requirementshub.ai for DPA and agreement requests.
Last updated: June 2026