01Current status, including the gaps
| Framework | Status | Detail |
|---|---|---|
| SOC 2 Type II | Not yet held | Controls are designed against the Trust Services Criteria. We have not completed an observation period or received a report. We will not claim otherwise. |
| SOC 2 Type I | Not yet held | Planned ahead of Type II. |
| ISO 27001 | Not held | Not currently planned. If a customer requires it we will say so rather than implying a timeline. |
| GDPR / UK GDPR | Compliant as processor | DPA available, Article 28 terms with subprocessors, SCCs and UK Addendum for transfers. |
| CCPA / CPRA and US state laws | Compliant as service provider | No sale or sharing of personal information. GPC honoured. Rights process published. |
| PCI-DSS | Out of scope | We never handle card data. Payment processing is performed by a PCI-compliant processor. |
| HIPAA | Not a covered entity | We do not process PHI. Healthcare customers connect financial rather than clinical data. BAA available where counsel requires one. |
If SOC 2 Type II is a hard procurement requirement today, we do not meet it. Tell us early and we will say so plainly rather than proposing a workaround. Some buyers can proceed on a security review and contractual commitments; others cannot, and that is a legitimate position.
02Controls in place regardless of certification
Certification attests that controls exist and operate. The controls themselves are what protect your data, and they exist now.
- Access control enforced in the data layer. Every query carries an actor and a scope; a query without them fails rather than returning the wrong rows. Row-level security in the database sits underneath as defence in depth.
- One permission model for every actor. People, agents, API credentials, and portal users are governed identically, so automated activity cannot fall outside the control framework.
- Append-only, hash-chained audit log. No actor, including our engineers, has an update or delete path. Alteration or removal is detectable.
- Break-glass production access. Time-bound, dual-approved, logged into the same audit trail, and reported to affected customers. Routine support does not include production data access.
- Encryption. TLS 1.2 or higher in transit; encryption at rest.
- Segregation of duties. Conflicting authority combinations are rejected at grant time rather than reported afterwards.
- Tested recovery. Restores exercised quarterly against production-sized data. RPO 5 minutes, RTO 4 hours for regional failure.
- Vendor review. Security assessment before engaging any subprocessor that touches Customer Data.
03Financial reporting standards
A question we are asked in most evaluations: is the software itself compliant with accounting standards? The honest answer has two parts.
Software does not make financial statements compliant. Preparation of financial statements in accordance with US GAAP or IFRS is the responsibility of your management and your accountants. No system can discharge that.
What we do provide is a ledger and control environment that supports it:
- double-entry, append-only accounting with corrections posted as reversals;
- revenue recognition supporting ASC 606 five-step treatment, with performance obligations, allocation, and the basis for each determination recorded;
- lease treatment inputs, accruals, prepaid amortisation, and period-close controls;
- multi-entity consolidation with transaction-level intercompany elimination and computed cumulative translation adjustment rather than a plug;
- an audit trail covering automated as well as human actions, which is what makes automated activity assertable; and
- read-only, scoped, expiring auditor access with its own logged activity.
Where a determination requires judgement — whether an obligation is distinct, whether a cost is capitalisable — the system records the determination and who made it. It does not make it for you, and an agent is not permitted to.
04Security reviews and questionnaires
We complete security questionnaires and participate in vendor reviews. Write to [email protected] and we will turn most around within five business days.
Available on request, under NDA where appropriate:
- a security overview describing architecture, controls, and data flows;
- our Data Processing Addendum, including SCCs and the UK Addendum;
- subprocessor list with locations and processing purposes;
- incident response and breach notification commitments;
- business continuity and disaster recovery summary, with tested RPO and RTO; and
- penetration test summary, where a current test exists.
Where a questionnaire asks whether we hold a certification we do not hold, we answer no. We do not answer “in progress” unless an engagement is actually underway with a named auditor.
05The risk we cannot certify away
The honest risk in buying from us is not a control failure. It is that we are a young company and you would be running finance operations on our software.
No certification addresses that. What addresses it is that a complete, current copy of your data sits in storage you control, produced automatically on a schedule you set, in open documented formats, including the audit trail. If we cease to exist, you hold a dataset a competent team can load elsewhere.
We recommend exercising that export during evaluation rather than after signing. Ask for a sample against a demo tenant, load it somewhere, and judge whether it is what you would need. Reluctance from any vendor to let you do that is itself informative.
Source code escrow is available on applicable plans. We say plainly that escrowed code without infrastructure or operational knowledge is worth considerably less than most buyers assume, and that the data is the asset worth protecting.
06Contact
For compliance documentation, questionnaires, or to discuss a requirement we do not currently meet, write to [email protected].
Nead, LLC (d/b/a DEV.co), 1425 Broadway 22689, Seattle, WA 98112, United States.