ARIA Trust Center

Compliance

Last reviewed: 2026-04-20 · v2.2.1-D

Framework coverage

FrameworkStatusNotes
SOC 2 Type IIIn progressObservation window Q1 2026; report Q3 2026.
ISO 27001RoadmapGap assessment complete; certification H2 2026.
HIPAABAA availableEnterprise tier; PHI-path isolation.
PCI DSSSAQ-AStripe hosted fields; no card data on ARIA.
GDPR / CCPA / PIPEDA / UAE-PDPLIn productionSee Data Protection page.
EU AI ActArt 13 conformantSee AI Governance page.

Audit artefacts on request

  • SOC 2 bridge letter (signed NDA required)
  • Penetration-test executive summary
  • Subprocessor register with data categories
  • Record of Processing Activities (Art 30) extract

Email compliance@simplification.io.