Compliance & Certifications
entropyDB is built toward the highest standards for data security, privacy, and compliance β here's exactly where each certification stands today.
SOC 2 Type II
PlannedIndependently audited for security, availability, and confidentiality controls.
Not yet started. Planned after the third-party penetration test, ahead of Cloud GA β see the product roadmap.
GDPR
PlannedFull compliance with EU General Data Protection Regulation requirements.
Not yet assessed. No formal GDPR compliance program exists today.
HIPAA
PlannedBusiness Associate Agreements available for healthcare data.
Not available today. No BAA program exists.
CCPA
PlannedCalifornia Consumer Privacy Act compliance for US customers.
Not yet assessed.
ISO 27001
PlannedInformation security management system certification.
Not yet started β planned to follow SOC 2, based on real customer demand rather than pursued speculatively.
PCI DSS
PlannedPayment Card Industry Data Security Standard compliance.
Not yet assessed; not applicable until payment-card data is handled directly.
Data Residency & Sovereignty
PlannedAvailable today: a single real AWS region (us-east-1). The multi-region footprint below is the target architecture, not yet built β see the product roadmap for the planned sequencing.
πΊπΈ United States
US East available today Β· US West (Planned)
πͺπΊ European Union
Germany, Ireland regions with GDPR compliance (Planned)
π Asia Pacific
Singapore, Tokyo, Sydney regions (Planned)
Your data never leaves your chosen region unless explicitly configured for replication.