Frameworks
| Framework | Status | Notes |
|---|---|---|
| SOC 2 Type II | Report in progress | Observation window closed; report expected Q4 2026. Type I report available under NDA. |
| ISO/IEC 27001 | Roadmap 2027 | ISMS controls documented; certification audit planned after SOC 2. |
| UK GDPR & EU GDPR | Compliant | Compliant. DPA available, data stored in the EU (Ireland), records of processing maintained. |
| EU AI Act | Aligned | Audit trail and human-oversight controls map to the transparency and logging obligations for high-risk systems. |
| HIPAA | Available | BAA offered on Enterprise plans; PHI stays within the EU (Ireland) database region. |
| PCI DSS | Not applicable | AnterisLab does not store, process or transmit cardholder data. Payment actions are decisions, not charges. |
Controller: SAASDEVSOLUTIONS LTD · Registered in England and Wales, Company Number 17362476 · Registered office: 167-169 Great Portland Street, 5th Floor, London, United Kingdom · Registered with the ICO.
Data & residency
- Customer data is stored in the European Union — Ireland. The application and edge delivery are deployed on Vercel in the United States; the database and its backups remain in the EU (Ireland). Self-hosting is available on Enterprise.
- Because requests are served from the United States while data rests in the EU (Ireland), international transfers rely on the UK International Data Transfer Addendum and the European Commission Standard Contractual Clauses — see Privacy Policy — International transfers.
- Decision context is retained for 30 days by default and configurable from 7 to 365 days. Audit records are retained for the contractual term.
- Data in transit is protected with TLS 1.2+; data at rest is encrypted with AES-256 and per-workspace keys.
- Sub-processor changes are announced at least 30 days in advance; customers may object and terminate without penalty.
Sub-processors
| Sub-processor | Purpose | Location | DPA |
|---|---|---|---|
| Supabase | Managed Postgres, authentication storage | EU (Ireland) | supabase.com/legal/dpa |
| Vercel | Application hosting, edge delivery and serverless API runtime | United States (deployment) | vercel.com/legal/dpa |
| Stripe | Subscription billing | UK / EU | stripe.com/legal/dpa |
| Resend | Transactional email delivery (password reset, email change, signup confirmation) | United States / EU | resend.com/legal/dpa |
| Zoho Mail | Business mailbox for support, security and compliance correspondence | EU / United States | zoho.com/privacy/dpa.html |
| GitHub | Source code hosting, CI/CD, dependency updates for the SDK and site | United States | github.com/customer-terms |
| GoatCounter | Cookie-free, anonymous site analytics | EU | goatcounter.com/help/privacy |
Audit requests
Security questionnaires, penetration-test summaries, DPAs and SOC reports are available to customers and prospects under NDA. Write to compliance@anterislab.com.
Public DPAs from our sub-processors are linked in the table above. If you need a countersigned DPA with SAASDEVSOLUTIONS LTD, write to legal@anterislab.com.