StandardStatusCoverageDocumentation

GDPR
Partially implemented
Records of processing (Art. 30), subject access and export (Art. 15), and retention limits enforced by a daily batched sweep (Art. 5(1)(e)) are implemented. Erasure (Art. 17) cascades through every workspace an organization owns and returns a receipt, with one deliberate exception: hash-chained audit evidence is retained, because erasing it would break the chain that proves everything else. Security of processing (Art. 32) is partial while TLS termination sits outside the application.
DPA, privacy notice, and breach runbook are in legal drafting, Art. 28 and Art. 33 are not yet met. Control status and evidence paths available under NDA today.

CCPA
Partially implemented
The same access, deletion, and portability controls satisfy California consumer rights. Memnox does not sell or share personal information.
Privacy notice and the Do Not Sell or Share disclosure ship with the GDPR drafting work.

SOC 2 Type 1
In progress
Independent attestation that our controls operate as designed. Access control, change management, and monitoring are partially implemented. Still to build: structured logging with correlation IDs, a signed SBOM attached to each release, enforced branch protection with per-release evidence, and, the largest gap, backups with a tested restore. We have no restore drill today, and an untested backup is not a control.
Current control status shared under NDA. Attestation follows the audit; Type II adds an observation window on top of it.

ISO 27001
In progress
Cryptographic controls are implemented. Logging and monitoring are partial. There is no ISMS, risk register, or Statement of Applicability yet, and no continuity plan.
Controls overview available today. Certification requires Stage 1 and Stage 2 audits by an accredited body.