This page describes source-level readiness, not a certification or legal opinion. Operational controls, contracts and live deployment settings must be verified separately during diligence.
Source evidence includes DPA/DPIA templates, export and erasure flows, RLS policies, and a hash-chained audit trail. This is not a legal attestation; each live deployment requires a records, contracts, and configuration review.
Last verified:
ISO/IEC 27001:2022
Readiness material only
Information Security Management System
An Annex A control inventory and policy templates exist in source. No certification, signed assessor engagement, or completed operational evidence set is evidenced by this repository.
Last verified:
SOC 2 Type II
Readiness material only
Security, Availability, Confidentiality TSCs
Selected security controls are observable in source, including RBAC, RLS, audit chaining, and secret encryption. No SOC report, observation window, or signed auditor engagement is evidenced by this repository.
Last verified:
BSI C5:2020
Readiness material only
Cloud Computing Compliance Criteria Catalogue
Mapped to ISO 27001 controls; type-2 attestation depends on completed 27001 audit (preceding line). Not yet contracted with a BSI-listed auditor.
Last verified:
TISAX (German automotive)
Not in scope
Information Security Assessment for automotive sector
No automotive supply-chain customers currently. Will revisit if vertical demand emerges.
Last verified:
HIPAA (US healthcare)
Not in scope
Protected Health Information processing
Orconic is not a Business Associate today. Service is not marketed for PHI workloads.
Last verified:
Penetration Testing
Not scheduled · Vendor: Not engaged · Status: not scheduled Scope: External web application + API + authenticated workspace flows No independent penetration-test report or signed engagement is evidenced by this repository. Source-level security tests and static checks do not replace an external assessment.
Need a signed copy of any report, DPA, or vendor questionnaire? security@codaiq.com.