Compliance Control Matrix
Last updated: March 2026
This matrix maps HAIEC's implemented controls to applicable regulatory frameworks. It describes design alignment, not certification. HAIEC has not completed formal audits for SOC 2, ISO 27001, HIPAA, or any other framework listed below.
Important Disclaimer
- SOC 2: Not yet audited. Working toward Type II. Infrastructure providers are SOC 2 certified.
- ISO 27001: Not certified. Controls designed with ISO 27001 principles in mind.
- HIPAA: Not a covered entity or business associate. Controls align with HIPAA Security Rule technical safeguards.
- GDPR: No "certification" exists. We describe design alignment with GDPR requirements.
- NYC LL144: HAIEC provides bias audit tooling. Compliance depends on how customers use the tool.
- CCPA: Aligned with consumer rights requirements. Not formally assessed.
Control Mapping
| HAIEC Control | SOC 2 | ISO 27001 | GDPR | HIPAA | NYC LL144 | CCPA |
|---|---|---|---|---|---|---|
| TLS 1.2+ encryption in transit | CC6.7 | A.13.2.3 | Art 32(1) | 164.312(e)(1) | N/A | 1798.150 |
| AES-256 encryption at rest (Neon) | CC6.7 | A.10.1.1 | Art 32(1) | 164.312(a)(2)(iv) | N/A | 1798.150 |
| OAuth 2.0 authentication (GitHub, Google) | CC6.1 | A.9.2.1 | Art 32(1) | 164.312(d) | N/A | N/A |
| Role-based access control (RBAC) | CC6.3 | A.9.4.1 | Art 32(1) | 164.312(d) | N/A | N/A |
| Tenant isolation at query level | CC6.1 | A.13.1.1 | Art 25 | 164.312(b) | N/A | 1798.100 |
| Audit logging of data access | CC7.2 | A.12.4.1 | Art 30 | 164.312(b) | N/A | 1798.130 |
| Rate limiting & abuse prevention | CC7.1 | A.12.6.1 | Art 32(1) | 164.312(c)(1) | N/A | N/A |
| Input validation (Zod schemas) | CC7.1 | A.14.2.5 | Art 32(1) | 164.312(c)(1) | N/A | N/A |
| Evidence integrity (SHA-256 hashing) | CC8.1 | A.18.1.3 | Art 32(1) | 164.312(c)(1) | Audit integrity | N/A |
| Deterministic compliance engines | CC8.1 | A.18.1.3 | N/A | N/A | Bias audit requirement | N/A |
| Breach notification process | CC7.3 | A.16.1.2 | Art 33 | 164.410 | N/A | 1798.82 |
| Data deletion on request | CC5.2 | A.8.3.3 | Art 17 | 164.530(j) | Candidate deletion | 1798.105 |
| Data Processing Agreement (DPA) | CC6.6 | A.18.1.3 | Art 28 | 164.314(b) | N/A | 1798.140(a) |
| Subprocessor management | CC6.6 | A.15.2.1 | Art 28(2) | 164.314(b) | N/A | N/A |
| Data minimization (no source code stored) | CC6.1 | A.8.2.1 | Art 5(1)(c) | 164.502(b) | N/A | 1798.100 |
| PII hashing before storage (NYC LL144) | CC6.7 | A.10.1.1 | Art 32(1)(a) | 164.312(a)(2)(iv) | Candidate privacy | 1798.100 |
| Vulnerability disclosure program | CC7.1 | A.16.1.1 | Art 32(2) | 164.308(a) | N/A | N/A |
| Error monitoring (Sentry) | CC7.2 | A.12.4.1 | Art 32(1) | 164.312(b) | N/A | N/A |
Framework Notes
SOC 2 (AICPA Trust Services Criteria)
Controls mapped to Common Criteria (CC) sections. HAIEC is working toward SOC 2 Type II audit. Infrastructure providers (Vercel, Neon, Modal, Stripe) hold their own SOC 2 Type II certifications.
ISO 27001 (Annex A)
Controls mapped to Annex A reference numbers. HAIEC is not ISO 27001 certified. Controls are designed with ISO 27001 principles in mind.
GDPR (General Data Protection Regulation)
Controls mapped to relevant articles. HAIEC maintains data processing records (Article 30), supports data subject rights, and provides a DPA (Article 28). No GDPR "certification" exists.
HIPAA (Health Insurance Portability and Accountability Act)
Controls mapped to Security Rule technical safeguard requirements (164.312). HAIEC is not a covered entity or business associate. Alignment is provided for customers who need to process healthcare data within their own compliance scope.
NYC Local Law 144 (Automated Employment Decision Tools)
HAIEC provides bias audit tooling for AEDT vendors. Candidate identifiers are hashed (SHA-256) before storage. Bias audit results are aggregate statistics only. Compliance depends on how customers configure and use the tool.
CCPA (California Consumer Privacy Act)
Controls mapped to relevant Civil Code sections. HAIEC supports deletion requests, data export, and does not sell personal data. Not formally assessed.