Skip to content

Compliance — Roadmap

  • Date: 2026-04-16
  • Status: Proposed
  • Depends on: security/threat-model.md, product/positioning.md

Research flagged compliance as procurement table stakes, not a post-launch add-on, for the Puccha ICP. Our buyers (insurance compliance officers, bank InfoSec, hospital DPOs) cannot close a contract without:

  • A Thai SCC-overlay DPA (Section 29 safeguards, 72h breach notification)
  • Evidence our LLM sub-processor (Anthropic) is governed
  • ISO 27001 certification or credible path
  • SOC 2 Type II on the roadmap
  • DPO appointment (ours, and help with theirs)

Waiting until month 12 to begin ISO 27001 kills the enterprise pipeline in month 3.

  • ISO 27001 readiness assessment (Certogo-led, ~2 weeks).
  • Statement of Applicability (SoA) drafted against Annex A controls.
  • Thai SCC template published with 72h breach notification overlay + Anthropic sub-processor reference.
  • Anthropic DPA signed (includes standard Anthropic commitments; we attach Thai overlay in sub-agreement).
  • Privacy policy (Thai + English) published at puccha.hxlab.io/legal/privacy.
  • Cookie policy + consent banner deployed on marketing + app.
  • Data-processing record (RoPA) started.
  • depa Digital Service Provider registration application submitted.
  • Sub-processor list published at puccha.hxlab.io/trust/subprocessors (Anthropic, Cloudflare, Stripe, Resend).
  • Information Security Management System (ISMS) scope documented.
  • Access control, change management, incident response, business continuity, supplier policies drafted.
  • Access review cadence set (quarterly).
  • DPIA template published for tenant use (aligned with PDPC guidance).
  • Audit log tamper-evidence (hash chaining) implemented.
  • Customer Data Processing Agreement template finalized; Thai legal review complete.
  • Thai SCC overlay reviewed by external Thai counsel (one of Tilleke, DLA Piper, Formichella & Sritawat).
  • Internal audit #1 run against ISMS; findings remediated.
  • Penetration test — external firm, scope = puccha.hxlab.io (all subpaths: /app, /api, /widget).
  • SOC 2 observation window starts (month 6) — evidence collection automated via Drata / Vanta [PROPOSED DEFAULT — Drata; Vanta alternative].
  • ISO 27001 Stage 1 audit (month 6).
  • Trust center live at puccha.hxlab.io/trust: subprocessors, policies, certifications-in-progress, incident history, security contacts.
  • Incident response runbook drilled — tabletop exercise including 72h PDPC notification flow.
  • Stage 2 audit (month 7–8).
  • ISO 27001 certificate issued (target month 9).
  • Announce ISO 27001 to pipeline + case studies.
  • SOC 2 Type I report prepared (month 9–10).
  • SCIM 2.0 shipped (required by enterprise SSO buyers).
  • SOC 2 Type I report available under NDA.
  • SOC 2 Type II observation window complete by month 12 (started month 6).
  • PDPA DPO attestation — Certogo-issued certificate for Puccha’s own DPO function; also offered as customer deliverable.
  • Customer audit-pack template published — one-click export for tenant audits.
  • Sovereignty toggle enabled (Anthropic EU or Bedrock ap-southeast-1 Claude).
  • SOC 2 Type II report issued (month 14–15).
  • Bug bounty launched (HackerOne or Intigriti).
  • Annual ISO 27001 surveillance audit (month 12-ish).
  • ISO 27701 readiness (privacy extension to 27001) — required by some buyers in financial services.
  • Cloud Security Alliance STAR Level 1 — self-assessment, free, adds credibility.
Artifact Free Team Business Enterprise
Sub-processor list
Privacy policy
Standard DPA
Thai SCC overlay (72h PDPC)
Custom DPA redlines accepted
ISO 27001 SoA (once certified)
SOC 2 Type II report (once issued)
Penetration test summary
Audit-pack export
DPO consult (quarterly) 1h/yr 4h/yr
DPO-as-a-service (Certogo) add-on bundled option
Dedicated uptime SLA 99.0 99.5 99.9 99.95 + credits
Data-residency toggle ✅ (EU or ap-southeast-1)
Customer-managed encryption keys

PDPA (Thailand, 2022 → enforcement 2024–2026)

Section titled “PDPA (Thailand, 2022 → enforcement 2024–2026)”
Requirement Puccha implementation
§ 23 data subject rights Export + erasure UIs for tenant admins; per-user download/delete endpoints
§ 28 cross-border transfer (inside Thailand) N/A; all processing outside TH without consent → § 29
§ 29 Appropriate Safeguards Thai SCC overlay with Anthropic + Cloudflare; BCR path for enterprise tenants
§ 37 security obligations ISMS + ISO 27001; technical + organizational measures documented
§ 40 DPO appointment Puccha has appointed DPO (via Certogo); customer deliverable available
§ 42 record-keeping RoPA maintained; audit log 90d–1y by tier
§ 72-hour breach notification (PDPC) Incident runbook hard-coded to 72h; drilled quarterly
Sub-processor transparency puccha.hxlab.io/trust/subprocessors publicly lists Anthropic, Cloudflare, Stripe, Resend

ISO 27001:2022 (roadmap — certify month 9)

Section titled “ISO 27001:2022 (roadmap — certify month 9)”

All 93 Annex A controls mapped in SoA. Critical ones:

  • A.5 Organizational controls — policies + DPO + supplier security.
  • A.6 People controls — background checks, security awareness.
  • A.7 Physical — N/A (fully cloud; Cloudflare’s ISO 27001 referenced).
  • A.8 Technological — access control, crypto, op-sec, network, app-sec.

BOT FPG 19/2599 (IT outsourcing for banks)

Section titled “BOT FPG 19/2599 (IT outsourcing for banks)”

Puccha maps as a “non-critical IT service provider” to banks. Required controls:

  • ISO 27001 alignment (covered by our cert).
  • Right-to-audit clause in MSA (honored for Business+).
  • Data residency + exit plan (sovereignty toggle + export tools).
  • Incident notification to bank within 2 hours (stricter than PDPC 72h — we offer contractual 1h to Enterprise).
  • Data security — ISO 27001 controls.
  • Application security — SAST/DAST in CI; annual pen test; bug bounty.
  • Identity & access management — SSO, MFA, SCIM, role-based access, audit log.
  • 72h cyber-incident reporting to OIC — mirrored in our breach runbook.
  • Board-level IT oversight — Puccha’s board reports + tenant audit-pack aligns with this.
  • Identify / Protect / Detect / Respond program — ISMS covers.
  • Documented policies + access controls — Puccha enforces per-doc ACL + audit.
  • Patient data boundary — default deny + role-specific scoping.
Sub-processor Purpose Data Jurisdiction Safeguard
Anthropic, Inc. Claude Haiku 4.5 inference (AI Gateway → Anthropic) Prompts + retrieved context US (or EU with sovereignty toggle) Anthropic DPA + Thai SCC overlay (§29 safeguards, 72h breach)
Cloudflare, Inc. Hosting, D1, R2, Vectorize, KV, Workers AI, AI Gateway All tenant data at rest + in transit US (edge is global) Cloudflare DPA + SCCs; ISO 27001 / SOC 2 / PCI DSS certified
Stripe, Inc. Payments Billing data only (no KM content) US (with Stripe Thailand entity for THB invoicing) Stripe DPA + PCI DSS; Thai entity for local settlements
Resend Transactional email Email address + message metadata US Resend DPA; SPF/DKIM; no KM content in emails
Sentry (optional, observability) Error reports Scrubbed stack traces, no PII US Sentry DPA; PII scrubber enforced; use sentry-local-self-hosted option for Enterprise

DPA chain for end-customer: Customer (Controller) → Puccha / C2G Labs / Certogo Co., Ltd. (Processor) → Anthropic, Cloudflare, Stripe, Resend, Sentry (Sub-processors).

Timeline from detection:

  • T+0h: Detection (alerting, customer report, or internal find).
  • T+1h: Triage team convened (eng lead, security eng, DPO, AE for affected tenant).
  • T+4h: Initial assessment complete — is this a notifiable PDPA breach? If yes, clock to PDPC = T+72h maximum.
  • T+8h: Affected tenants notified with initial details.
  • T+24h: Remediation path documented; forensic scope confirmed.
  • T+48h: PDPC pre-filing draft ready.
  • T+60h: PDPC filing submitted (PDPA.or.th portal).
  • T+72h: PDPC filing deadline — SLA green; full post-mortem scheduled.
  • T+7d: Public post-mortem published at puccha.hxlab.io/status/incidents/<id>.

Drilled quarterly via tabletop exercise; documented in SOC 2 evidence collection.

  • Quarterly board review: compliance status, incidents, certification progress, DPIA results on new features.
  • Annual management review (required by ISO 27001 A.5.1.2).
  • DPO reports to board; has direct escalation path.
  • HIPAA — US healthcare; not our ICP. Revisit if hospital tenants export to US operations.
  • PCI DSS — we don’t process cardholder data directly (Stripe does).
  • FedRAMP — US gov; not applicable.
  • ISO 27017 / 27018 — cloud-specific add-ons to 27001; v2 consideration.
  • GDPR lead supervisory authority — defer; route EU tenants through Irish DPC if EU sovereignty toggle used.