SOC 2 Type II
In program · Target Q4 2026
Control framework aligned to AICPA Trust Services Criteria; formal attestation on roadmap (SEC-1)
Trust & security
Encryption in transit, role-based access, and AWS-native isolation — with a formal compliance program in progress for enterprise buyers.
Posture & controls
Honest certification status plus AWS-native controls your security team can review — open OCPP, gated provisioning, Cognito SSO, and operator RBAC with per-app database schemas.
In program · Target Q4 2026
Control framework aligned to AICPA Trust Services Criteria; formal attestation on roadmap (SEC-1)
Aligned
Security management practices mapped to ISO controls — formal cert may be required for some RFPs; security briefing available
Ready
Data residency, access controls, and audit-friendly RDS schemas
Production
EKS, IoT OCPP, Cognito SSO, VPC-isolated RDS
EKS workloads, IoT OCPP gateway, Cognito SSO, and VPC-isolated RDS with a dedicated schema per application — not a shared multi-tenant grab bag.
SOC 2 Type II in program (target Q4 2026), ISO 27001-aligned practices, and GDPR/CCPA-ready data controls for operator and driver records.
OCPP 1.6J in production on AWS IoT Core, OCPP 2.x on the roadmap — open protocol handoff without lock-in to a closed CSMS stack.
VPN-gated onboarding, ALB-classified edge, TLS 1.2+, and RBAC across admin, operator, and viewer roles with audit-friendly change history.