Compliance roadmap
Where Silos stands on SOC 2, HIPAA, ISO 27001, and GDPR today — and what is planned. Silos is not yet certified.
This page exists to be unambiguous about compliance, because it is the area where vague language does the most harm.
Silos is not yet certified or compliant with SOC 2, HIPAA, ISO 27001, GDPR, or any similar framework. Formal compliance work has not been completed. The items below are roadmap goals, not current attestations. Do not treat Silos as certified for any of these frameworks today.
Current status
Silos is in active development. We have built real security controls — per-tenant isolation, encryption in transit and at rest, SCRAM-SHA-256 authentication, and audit logging — but those controls are not the same as a certification. A certification requires an independent audit, formal evidence, and a report from an accredited body, none of which Silos currently holds.
| Framework | Status today |
|---|---|
| SOC 2 (Type I / II) | Not certified. Planned. |
| HIPAA | Not compliant. Planned. No BAA is offered today. |
| ISO 27001 | Not certified. Planned. |
| GDPR | No compliance attestation today. Planned. No DPA is offered today. |
What "planned" means
"Planned" means it is on our roadmap, not that work is finished or that a date is committed. We will update this page — and publish the relevant reports and agreements — only when a control is independently attested. Until an entry on this page says a certification has been achieved, assume it has not.
If you have regulated workloads today
If your use case requires SOC 2, HIPAA, ISO 27001, GDPR, or another compliance regime right now, Silos cannot meet that requirement yet. Please:
- Treat the platform as not certified in any procurement, security review, or risk assessment.
- Contact us to discuss your requirements and timelines so we can be straight with you about whether and when Silos can fit.