Compliance — Roadmap
- Date: 2026-04-16
- Status: Proposed
- Depends on:
security/threat-model.md,product/positioning.md
Why this document exists
Section titled “Why this document exists”Research flagged compliance as procurement table stakes, not a post-launch add-on, for the Puccha ICP. Our buyers (insurance compliance officers, bank InfoSec, hospital DPOs) cannot close a contract without:
- A Thai SCC-overlay DPA (Section 29 safeguards, 72h breach notification)
- Evidence our LLM sub-processor (Anthropic) is governed
- ISO 27001 certification or credible path
- SOC 2 Type II on the roadmap
- DPO appointment (ours, and help with theirs)
Waiting until month 12 to begin ISO 27001 kills the enterprise pipeline in month 3.
Month-by-month plan
Section titled “Month-by-month plan”Month 1 — Foundation
Section titled “Month 1 — Foundation”- ISO 27001 readiness assessment (Certogo-led, ~2 weeks).
- Statement of Applicability (SoA) drafted against Annex A controls.
- Thai SCC template published with 72h breach notification overlay + Anthropic sub-processor reference.
- Anthropic DPA signed (includes standard Anthropic commitments; we attach Thai overlay in sub-agreement).
- Privacy policy (Thai + English) published at
puccha.hxlab.io/legal/privacy. - Cookie policy + consent banner deployed on marketing + app.
- Data-processing record (RoPA) started.
- depa Digital Service Provider registration application submitted.
- Sub-processor list published at
puccha.hxlab.io/trust/subprocessors(Anthropic, Cloudflare, Stripe, Resend).
Month 2–3 — Controls implementation
Section titled “Month 2–3 — Controls implementation”- Information Security Management System (ISMS) scope documented.
- Access control, change management, incident response, business continuity, supplier policies drafted.
- Access review cadence set (quarterly).
- DPIA template published for tenant use (aligned with PDPC guidance).
- Audit log tamper-evidence (hash chaining) implemented.
- Customer Data Processing Agreement template finalized; Thai legal review complete.
- Thai SCC overlay reviewed by external Thai counsel (one of Tilleke, DLA Piper, Formichella & Sritawat).
Month 4–6 — Operate + evidence
Section titled “Month 4–6 — Operate + evidence”- Internal audit #1 run against ISMS; findings remediated.
- Penetration test — external firm, scope = puccha.hxlab.io (all subpaths: /app, /api, /widget).
- SOC 2 observation window starts (month 6) — evidence collection automated via Drata / Vanta [PROPOSED DEFAULT — Drata; Vanta alternative].
- ISO 27001 Stage 1 audit (month 6).
- Trust center live at
puccha.hxlab.io/trust: subprocessors, policies, certifications-in-progress, incident history, security contacts. - Incident response runbook drilled — tabletop exercise including 72h PDPC notification flow.
Month 7–9 — Certification
Section titled “Month 7–9 — Certification”- Stage 2 audit (month 7–8).
- ISO 27001 certificate issued (target month 9).
- Announce ISO 27001 to pipeline + case studies.
- SOC 2 Type I report prepared (month 9–10).
- SCIM 2.0 shipped (required by enterprise SSO buyers).
Month 10–12 — Enterprise readiness
Section titled “Month 10–12 — Enterprise readiness”- SOC 2 Type I report available under NDA.
- SOC 2 Type II observation window complete by month 12 (started month 6).
- PDPA DPO attestation — Certogo-issued certificate for Puccha’s own DPO function; also offered as customer deliverable.
- Customer audit-pack template published — one-click export for tenant audits.
- Sovereignty toggle enabled (Anthropic EU or Bedrock ap-southeast-1 Claude).
Month 13–18 — Scale
Section titled “Month 13–18 — Scale”- SOC 2 Type II report issued (month 14–15).
- Bug bounty launched (HackerOne or Intigriti).
- Annual ISO 27001 surveillance audit (month 12-ish).
- ISO 27701 readiness (privacy extension to 27001) — required by some buyers in financial services.
- Cloud Security Alliance STAR Level 1 — self-assessment, free, adds credibility.
Compliance deliverables included per tier
Section titled “Compliance deliverables included per tier”| Artifact | Free | Team | Business | Enterprise |
|---|---|---|---|---|
| Sub-processor list | ✅ | ✅ | ✅ | ✅ |
| Privacy policy | ✅ | ✅ | ✅ | ✅ |
| Standard DPA | — | ✅ | ✅ | ✅ |
| Thai SCC overlay (72h PDPC) | — | ✅ | ✅ | ✅ |
| Custom DPA redlines accepted | — | — | ✅ | ✅ |
| ISO 27001 SoA (once certified) | — | — | ✅ | ✅ |
| SOC 2 Type II report (once issued) | — | — | — | ✅ |
| Penetration test summary | — | — | ✅ | ✅ |
| Audit-pack export | — | — | ✅ | ✅ |
| DPO consult (quarterly) | — | — | 1h/yr | 4h/yr |
| DPO-as-a-service (Certogo) | — | — | add-on | bundled option |
| Dedicated uptime SLA | 99.0 | 99.5 | 99.9 | 99.95 + credits |
| Data-residency toggle | — | — | — | ✅ (EU or ap-southeast-1) |
| Customer-managed encryption keys | — | — | — | ✅ |
Regulatory controls map (what-we-satisfy)
Section titled “Regulatory controls map (what-we-satisfy)”PDPA (Thailand, 2022 → enforcement 2024–2026)
Section titled “PDPA (Thailand, 2022 → enforcement 2024–2026)”| Requirement | Puccha implementation |
|---|---|
| § 23 data subject rights | Export + erasure UIs for tenant admins; per-user download/delete endpoints |
| § 28 cross-border transfer (inside Thailand) | N/A; all processing outside TH without consent → § 29 |
| § 29 Appropriate Safeguards | Thai SCC overlay with Anthropic + Cloudflare; BCR path for enterprise tenants |
| § 37 security obligations | ISMS + ISO 27001; technical + organizational measures documented |
| § 40 DPO appointment | Puccha has appointed DPO (via Certogo); customer deliverable available |
| § 42 record-keeping | RoPA maintained; audit log 90d–1y by tier |
| § 72-hour breach notification (PDPC) | Incident runbook hard-coded to 72h; drilled quarterly |
| Sub-processor transparency | puccha.hxlab.io/trust/subprocessors publicly lists Anthropic, Cloudflare, Stripe, Resend |
ISO 27001:2022 (roadmap — certify month 9)
Section titled “ISO 27001:2022 (roadmap — certify month 9)”All 93 Annex A controls mapped in SoA. Critical ones:
- A.5 Organizational controls — policies + DPO + supplier security.
- A.6 People controls — background checks, security awareness.
- A.7 Physical — N/A (fully cloud; Cloudflare’s ISO 27001 referenced).
- A.8 Technological — access control, crypto, op-sec, network, app-sec.
BOT FPG 19/2599 (IT outsourcing for banks)
Section titled “BOT FPG 19/2599 (IT outsourcing for banks)”Puccha maps as a “non-critical IT service provider” to banks. Required controls:
- ISO 27001 alignment (covered by our cert).
- Right-to-audit clause in MSA (honored for Business+).
- Data residency + exit plan (sovereignty toggle + export tools).
- Incident notification to bank within 2 hours (stricter than PDPC 72h — we offer contractual 1h to Enterprise).
SEC Chapter 2 (capital markets)
Section titled “SEC Chapter 2 (capital markets)”- Data security — ISO 27001 controls.
- Application security — SAST/DAST in CI; annual pen test; bug bounty.
- Identity & access management — SSO, MFA, SCIM, role-based access, audit log.
OIC IT-risk framework (insurers)
Section titled “OIC IT-risk framework (insurers)”- 72h cyber-incident reporting to OIC — mirrored in our breach runbook.
- Board-level IT oversight — Puccha’s board reports + tenant audit-pack aligns with this.
- Identify / Protect / Detect / Respond program — ISMS covers.
HA accreditation (private hospitals)
Section titled “HA accreditation (private hospitals)”- Documented policies + access controls — Puccha enforces per-doc ACL + audit.
- Patient data boundary — default deny + role-specific scoping.
Legal + sub-processor inventory
Section titled “Legal + sub-processor inventory”| Sub-processor | Purpose | Data | Jurisdiction | Safeguard |
|---|---|---|---|---|
| Anthropic, Inc. | Claude Haiku 4.5 inference (AI Gateway → Anthropic) | Prompts + retrieved context | US (or EU with sovereignty toggle) | Anthropic DPA + Thai SCC overlay (§29 safeguards, 72h breach) |
| Cloudflare, Inc. | Hosting, D1, R2, Vectorize, KV, Workers AI, AI Gateway | All tenant data at rest + in transit | US (edge is global) | Cloudflare DPA + SCCs; ISO 27001 / SOC 2 / PCI DSS certified |
| Stripe, Inc. | Payments | Billing data only (no KM content) | US (with Stripe Thailand entity for THB invoicing) | Stripe DPA + PCI DSS; Thai entity for local settlements |
| Resend | Transactional email | Email address + message metadata | US | Resend DPA; SPF/DKIM; no KM content in emails |
| Sentry (optional, observability) | Error reports | Scrubbed stack traces, no PII | US | Sentry DPA; PII scrubber enforced; use sentry-local-self-hosted option for Enterprise |
DPA chain for end-customer: Customer (Controller) → Puccha / C2G Labs / Certogo Co., Ltd. (Processor) → Anthropic, Cloudflare, Stripe, Resend, Sentry (Sub-processors).
Incident response (72h PDPC window)
Section titled “Incident response (72h PDPC window)”Timeline from detection:
- T+0h: Detection (alerting, customer report, or internal find).
- T+1h: Triage team convened (eng lead, security eng, DPO, AE for affected tenant).
- T+4h: Initial assessment complete — is this a notifiable PDPA breach? If yes, clock to PDPC = T+72h maximum.
- T+8h: Affected tenants notified with initial details.
- T+24h: Remediation path documented; forensic scope confirmed.
- T+48h: PDPC pre-filing draft ready.
- T+60h: PDPC filing submitted (PDPA.or.th portal).
- T+72h: PDPC filing deadline — SLA green; full post-mortem scheduled.
- T+7d: Public post-mortem published at
puccha.hxlab.io/status/incidents/<id>.
Drilled quarterly via tabletop exercise; documented in SOC 2 evidence collection.
Board / governance
Section titled “Board / governance”- Quarterly board review: compliance status, incidents, certification progress, DPIA results on new features.
- Annual management review (required by ISO 27001 A.5.1.2).
- DPO reports to board; has direct escalation path.
Out-of-scope (deferred)
Section titled “Out-of-scope (deferred)”- HIPAA — US healthcare; not our ICP. Revisit if hospital tenants export to US operations.
- PCI DSS — we don’t process cardholder data directly (Stripe does).
- FedRAMP — US gov; not applicable.
- ISO 27017 / 27018 — cloud-specific add-ons to 27001; v2 consideration.
- GDPR lead supervisory authority — defer; route EU tenants through Irish DPC if EU sovereignty toggle used.