Compliance & Certifications
Meeting the highest standards. Outermind is designed to help you meet your regulatory obligations with built-in compliance controls and regional data residency.
Regulatory Compliance
Regional and global regulatory frameworks we support
| Regulation | Coverage | Status |
|---|---|---|
πͺπΊ EU GDPR General Data Protection Regulation | EU Region | Compliant |
π¬π§ UK GDPR UK Data Protection Framework | UK Region | Compliant |
πΊπΈ CCPA/CPRA California Consumer Privacy Act | US Region | Compliant |
π¦πΊ Privacy Act 1988 Australian Privacy Act | AU Region | Compliant |
π₯ HIPAA Health Insurance Portability and Accountability Act | All Regions | Compliant |
π‘ SOC 2 Service Organization Control 2 | All Regions | Type I In Progress |
Data Processing Principles
Our approach to data handling follows privacy-by-design principles
Data Minimization
We only collect and process data that is strictly necessary for service delivery. No excessive data collection or retention.
Purpose Limitation
Data is used only for the stated purposes outlined in our privacy policy and your service agreement.
Storage Limitation
Configurable retention policies allow you to control how long data is stored. Automatic cleanup when no longer needed.
Accuracy
Tools for data correction and updates. Subject access requests processed within regulatory timeframes.
Security Certifications
Industry-standard security certifications and frameworks
EU GDPR
CompliantGeneral Data Protection Regulation
Full compliance with EU data processing requirements
UK GDPR
CompliantUK General Data Protection Regulation
Compliant with UK data protection framework
CCPA/CPRA
CompliantCalifornia Consumer Privacy Act
California consumer privacy rights supported
Privacy Act
CompliantPrivacy Act 1988 (Australia)
Australian privacy principles followed
SOC 2
In ProgressService Organization Control 2
Not yet certified: Type I documentation in progress, Type II targeted early 2027
HIPAA
AvailableHealth Insurance Portability and Accountability Act
BAA available for healthcare organizations
Request Compliance Documents
For enterprise customers, we provide comprehensive compliance documentation
Data Processing Agreement (DPA)
Standard contractual clauses for GDPR compliance and data processor obligations.
Sub-processor List
Complete list of third-party processors with their roles, locations, and data access scope.
Security Questionnaire Responses
Pre-filled responses to common security questionnaires (CAIQ, SIG, VSAQ).
Penetration Test Summary
Executive summary of latest third-party penetration testing results.
SOC 2 Report
Coming SoonWe do not have a SOC 2 report yet. Type I documentation is in progress now, with the Type II report targeted for early 2027. Both will be available under NDA for enterprise customers once issued.
Questions About Compliance?
Our team can help you understand how Outermind meets your specific regulatory requirements.