Compliance & Certifications

Meeting the highest standards. Outermind is designed to help you meet your regulatory obligations with built-in compliance controls and regional data residency.

Regulatory Compliance

Regional and global regulatory frameworks we support

RegulationCoverageStatus
πŸ‡ͺπŸ‡Ί
EU GDPR
General Data Protection Regulation
EU RegionCompliant
πŸ‡¬πŸ‡§
UK GDPR
UK Data Protection Framework
UK RegionCompliant
πŸ‡ΊπŸ‡Έ
CCPA/CPRA
California Consumer Privacy Act
US RegionCompliant
πŸ‡¦πŸ‡Ί
Privacy Act 1988
Australian Privacy Act
AU RegionCompliant
πŸ₯
HIPAA
Health Insurance Portability and Accountability Act
All RegionsCompliant
πŸ›‘
SOC 2
Service Organization Control 2
All RegionsType I In Progress

Data Processing Principles

Our approach to data handling follows privacy-by-design principles

Data Minimization

We only collect and process data that is strictly necessary for service delivery. No excessive data collection or retention.

Purpose Limitation

Data is used only for the stated purposes outlined in our privacy policy and your service agreement.

Storage Limitation

Configurable retention policies allow you to control how long data is stored. Automatic cleanup when no longer needed.

Accuracy

Tools for data correction and updates. Subject access requests processed within regulatory timeframes.

Security Certifications

Industry-standard security certifications and frameworks

EU GDPR

Compliant

General Data Protection Regulation

Full compliance with EU data processing requirements

UK GDPR

Compliant

UK General Data Protection Regulation

Compliant with UK data protection framework

CCPA/CPRA

Compliant

California Consumer Privacy Act

California consumer privacy rights supported

Privacy Act

Compliant

Privacy Act 1988 (Australia)

Australian privacy principles followed

SOC 2

In Progress

Service Organization Control 2

Not yet certified: Type I documentation in progress, Type II targeted early 2027

HIPAA

Available

Health Insurance Portability and Accountability Act

BAA available for healthcare organizations

Request Compliance Documents

For enterprise customers, we provide comprehensive compliance documentation

Data Processing Agreement (DPA)

Standard contractual clauses for GDPR compliance and data processor obligations.

Sub-processor List

Complete list of third-party processors with their roles, locations, and data access scope.

Security Questionnaire Responses

Pre-filled responses to common security questionnaires (CAIQ, SIG, VSAQ).

Penetration Test Summary

Executive summary of latest third-party penetration testing results.

SOC 2 Report

Coming Soon

We do not have a SOC 2 report yet. Type I documentation is in progress now, with the Type II report targeted for early 2027. Both will be available under NDA for enterprise customers once issued.

Questions About Compliance?

Our team can help you understand how Outermind meets your specific regulatory requirements.