Compliance posture
Six frameworks. Each carries the honest status text. When a certification lands, this page updates at the substrate — every deck, one-pager, and marketing surface that reads from it updates the same day.
Framework by framework
| Framework | Status | Note |
|---|---|---|
| SOC 2 Type II | In progress | Controls implemented against the trust-services criteria; observation window and independent audit under way. Report not yet issued. |
| ISO 27001:2022 | Not yet held | Substrate technical controls implemented; the information security management system is in preparation. Certificate not yet held. |
| EU AI Act · Annex IV | Pack in preparation | Technical documentation pack being assembled ahead of the 2027-08-02 obligation date. Substrate is being built to the Annex-IV structure from day one. |
| HIPAA | Readiness | Substrate technical safeguards implemented; BAA and administrative safeguards not yet in place. Do not treat the platform as HIPAA-covered until we do. |
| FERPA | Preventive | The Nebbos substrate does not currently process individual student records. Preventive controls in place so nothing crosses that line without notice. |
| GDPR · CCPA | DPA available | Data processing addendum at nebbos.ai/legal/dpa. Data-subject rights implemented as first-class flows, not as a support ticket. |
Read this before citing status. Retracted claims from an earlier marketing wave are permanently retired: “SOC 2 Type II certified” (past tense), “SOC 2 report available under NDA,” “Annex IV pack available under NDA.” These phrases MUST NOT appear on any Nebbos surface. Status text on this page is the authoritative wording; every marketing surface renders from it.
How this page stays honest
Every row above renders from a canonical claim substrate. The same substrate powers the compliance slide on the institutional deck, the compliance section on the fact sheet, and the compliance block on the security model. When the underlying status text changes, every surface changes with it.
Requesting a letter
Ask enterprise@nebbos.ai for the specific letter your compliance officer needs. Common asks:
- SOC 2 progress statement (under NDA)
- ISO 27001 substrate-controls attestation
- EU AI Act Annex IV pack current-state (under NDA)
- HIPAA readiness statement
- GDPR DPA execution copy