Compliance & Certifications

entropyDB is built toward the highest standards for data security, privacy, and compliance β€” here's exactly where each certification stands today.

SOC 2 Type II

Planned

Independently audited for security, availability, and confidentiality controls.

Not yet started. Planned after the third-party penetration test, ahead of Cloud GA β€” see the product roadmap.

GDPR

Planned

Full compliance with EU General Data Protection Regulation requirements.

Not yet assessed. No formal GDPR compliance program exists today.

HIPAA

Planned

Business Associate Agreements available for healthcare data.

Not available today. No BAA program exists.

CCPA

Planned

California Consumer Privacy Act compliance for US customers.

Not yet assessed.

ISO 27001

Planned

Information security management system certification.

Not yet started β€” planned to follow SOC 2, based on real customer demand rather than pursued speculatively.

PCI DSS

Planned

Payment Card Industry Data Security Standard compliance.

Not yet assessed; not applicable until payment-card data is handled directly.

Data Residency & Sovereignty

Planned

Available today: a single real AWS region (us-east-1). The multi-region footprint below is the target architecture, not yet built β€” see the product roadmap for the planned sequencing.

πŸ‡ΊπŸ‡Έ United States

US East available today Β· US West (Planned)

πŸ‡ͺπŸ‡Ί European Union

Germany, Ireland regions with GDPR compliance (Planned)

🌏 Asia Pacific

Singapore, Tokyo, Sydney regions (Planned)

Your data never leaves your chosen region unless explicitly configured for replication.