Aditya Labs is built on trusted, certified infrastructure. Your data is encrypted, protected, and never used for AI training.
Platform designed to support GDPR requirements (data rights, DPA, breach notification). Not independently audited.
Since: 2024
AI transparency and disclosure built in. Limited-risk classification. Not independently audited.
Since: 2025
Platform supports CCPA/CPRA rights (access, deletion, no data sale). Not independently audited.
Since: 2024
Payment processing handled entirely by Stripe (PCI DSS Level 1 certified). Aditya Labs does not store card data.
Since: N/A
Service Organization Control audit — targeting Q3 2026 completion
Since: 2026 Q3
Information security management system — roadmap item
Since: 2026 Q4
Platform is not HIPAA certified and we do not sign BAAs. Our dental product avoids storing PHI.
Since: N/A
AI management system — roadmap item aligned with EU AI Act principles
Since: 2027
We are actively pursuing SOC 2 Type II certification. Here is our timeline.
Identifying control gaps and documenting security policies.
Implementing required security controls, policies, and procedures.
Pre-audit review with external auditor to validate readiness.
3-6 month observation period by certified auditor.
SOC 2 Type II report issued and available to enterprise customers.
| Provider | Purpose | Location |
|---|---|---|
| Vercel | Application hosting and edge network | US / Global CDN |
| Supabase | Database, authentication, real-time subscriptions | US (AWS) |
| OpenAI | AI model provider for chatbot responses | US |
| Stripe | Payment processing and billing | US / EU |
| Resend | Transactional email delivery | US |
| Twilio | SMS and WhatsApp message delivery | US / Global |
| Meta (Facebook) | Instagram DM and Messenger APIs | US / EU |
| Telegram | Telegram Bot API | Global |
Our security team is happy to answer questions, provide documentation, or discuss your specific compliance requirements.