Skip to main content

Compliance Control Matrix

Last updated: March 2026

This matrix maps HAIEC's implemented controls to applicable regulatory frameworks. It describes design alignment, not certification. HAIEC has not completed formal audits for SOC 2, ISO 27001, HIPAA, or any other framework listed below.

Important Disclaimer

  • SOC 2: Not yet audited. Working toward Type II. Infrastructure providers are SOC 2 certified.
  • ISO 27001: Not certified. Controls designed with ISO 27001 principles in mind.
  • HIPAA: Not a covered entity or business associate. Controls align with HIPAA Security Rule technical safeguards.
  • GDPR: No "certification" exists. We describe design alignment with GDPR requirements.
  • NYC LL144: HAIEC provides bias audit tooling. Compliance depends on how customers use the tool.
  • CCPA: Aligned with consumer rights requirements. Not formally assessed.

Control Mapping

HAIEC ControlSOC 2ISO 27001GDPRHIPAANYC LL144CCPA
TLS 1.2+ encryption in transitCC6.7A.13.2.3Art 32(1)164.312(e)(1)N/A1798.150
AES-256 encryption at rest (Neon)CC6.7A.10.1.1Art 32(1)164.312(a)(2)(iv)N/A1798.150
OAuth 2.0 authentication (GitHub, Google)CC6.1A.9.2.1Art 32(1)164.312(d)N/AN/A
Role-based access control (RBAC)CC6.3A.9.4.1Art 32(1)164.312(d)N/AN/A
Tenant isolation at query levelCC6.1A.13.1.1Art 25164.312(b)N/A1798.100
Audit logging of data accessCC7.2A.12.4.1Art 30164.312(b)N/A1798.130
Rate limiting & abuse preventionCC7.1A.12.6.1Art 32(1)164.312(c)(1)N/AN/A
Input validation (Zod schemas)CC7.1A.14.2.5Art 32(1)164.312(c)(1)N/AN/A
Evidence integrity (SHA-256 hashing)CC8.1A.18.1.3Art 32(1)164.312(c)(1)Audit integrityN/A
Deterministic compliance enginesCC8.1A.18.1.3N/AN/ABias audit requirementN/A
Breach notification processCC7.3A.16.1.2Art 33164.410N/A1798.82
Data deletion on requestCC5.2A.8.3.3Art 17164.530(j)Candidate deletion1798.105
Data Processing Agreement (DPA)CC6.6A.18.1.3Art 28164.314(b)N/A1798.140(a)
Subprocessor managementCC6.6A.15.2.1Art 28(2)164.314(b)N/AN/A
Data minimization (no source code stored)CC6.1A.8.2.1Art 5(1)(c)164.502(b)N/A1798.100
PII hashing before storage (NYC LL144)CC6.7A.10.1.1Art 32(1)(a)164.312(a)(2)(iv)Candidate privacy1798.100
Vulnerability disclosure programCC7.1A.16.1.1Art 32(2)164.308(a)N/AN/A
Error monitoring (Sentry)CC7.2A.12.4.1Art 32(1)164.312(b)N/AN/A

Framework Notes

SOC 2 (AICPA Trust Services Criteria)

Controls mapped to Common Criteria (CC) sections. HAIEC is working toward SOC 2 Type II audit. Infrastructure providers (Vercel, Neon, Modal, Stripe) hold their own SOC 2 Type II certifications.

ISO 27001 (Annex A)

Controls mapped to Annex A reference numbers. HAIEC is not ISO 27001 certified. Controls are designed with ISO 27001 principles in mind.

GDPR (General Data Protection Regulation)

Controls mapped to relevant articles. HAIEC maintains data processing records (Article 30), supports data subject rights, and provides a DPA (Article 28). No GDPR "certification" exists.

HIPAA (Health Insurance Portability and Accountability Act)

Controls mapped to Security Rule technical safeguard requirements (164.312). HAIEC is not a covered entity or business associate. Alignment is provided for customers who need to process healthcare data within their own compliance scope.

NYC Local Law 144 (Automated Employment Decision Tools)

HAIEC provides bias audit tooling for AEDT vendors. Candidate identifiers are hashed (SHA-256) before storage. Bias audit results are aggregate statistics only. Compliance depends on how customers configure and use the tool.

CCPA (California Consumer Privacy Act)

Controls mapped to relevant Civil Code sections. HAIEC supports deletion requests, data export, and does not sell personal data. Not formally assessed.