Trust Center

Compliance & Regulatory Posture

Last Updated: June 2026

Overview

This page states what RequirementsHub's compliance posture actually is — not what sounds impressive. Procurement teams, security reviewers, and customers should be able to make informed decisions based on facts, not aspirations. Where a framework is "in progress" or "not supported," we say so plainly.

SOC 2

ItemStatus
Type II reportNot yet issued
Audit firmTo be selected
Trust Service Criteria in scopeSecurity, Availability, Confidentiality (planned)
Target timelineAudit initiation planned within 6 months; Type I report targeted within 12 months; Type II observation window to follow
Compensating evidence available todaySubprocessor SOC 2 reports (Cloudflare, Supabase, Stripe), this Trust Center, our Security and Data Handling pages, DPA
Bridge lettersNot applicable until first report is issued

GDPR

ItemStatus
RoleData Processor for customer-uploaded content; Data Controller for our own account and billing data
Lawful basis for processingContract (Article 6(1)(b)) for service delivery; Legitimate interest for security and product reliability
DPAPublished at requirementshub.ai/trust/dpa; auto-incorporated into customer agreement on Pro and Enterprise plans
Standard Contractual ClausesModule 2 (Controller-to-Processor) included in the DPA Annex for EEA / UK / Swiss transfers
Data subject rightsSelf-service export and deletion via /account/data; manual requests via privacy@requirementshub.ai
Breach notification72 hours from confirmation (see Incident Response)
EU representativeNot currently appointed; available on request for Enterprise customers

UK GDPR

The UK GDPR mirrors the EU GDPR. RequirementsHub treats UK personal data on the same basis as EEA personal data and includes the UK International Data Transfer Addendum (IDTA) in the DPA for transfers from the UK.

HIPAA

ItemStatus
HIPAA-covered serviceNo
Business Associate Agreement (BAA)Not offered
PHI permitted on the platformNo — see Acceptable Use Policy
RequirementsHub is not a HIPAA-covered service and does not sign Business Associate Agreements. Protected Health Information must not be uploaded to the platform. Healthcare teams using RequirementsHub for requirements analysis should ensure source documents are scrubbed of PHI before upload, or use synthetic / representative data.

CCPA / CPRA

ItemStatus
Role under CCPAService Provider to business customers; Business for our own account and billing data
Sale or sharing of personal informationWe do not sell or share personal information for cross-context behavioral advertising
Consumer rights (access, delete, correct, portability)Honored via /account/data self-service and privacy@requirementshub.ai
Sensitive personal informationLimited processing; see Privacy Policy

PCI DSS

ItemStatus
Cardholder data stored, transmitted, or processed by RequirementsHubNone — payment processing is fully outsourced to Stripe
Stripe PCI DSS levelLevel 1 (highest)
Our PCI scopeSAQ A eligible (no cardholder data touches our environment)

Export Controls

ItemStatus
Service classificationCommercial SaaS; no encryption product export classification claimed
Sanctioned jurisdictionsWe do not knowingly provide service to users or organizations in OFAC-sanctioned jurisdictions
Export-controlled technical dataProhibited from upload — see Acceptable Use Policy

Roadmap

MilestoneTarget
SOC 2 audit firm selectedWithin 3 months
SOC 2 readiness assessment completeWithin 6 months
First penetration test (third-party)Concurrent with SOC 2 readiness
SOC 2 Type I report issuedWithin 12 months
SOC 2 Type II observation window completeWithin 18–24 months
MFA generally available for customer accountsWithin 6 months
Public status pageWithin 3 months
Formal vulnerability disclosure / bounty programAfter SOC 2 Type I

Questions

Contact security@requirementshub.ai for security and audit inquiries, or legal@requirementshub.ai for DPA and agreement requests.

Last updated: June 2026