Compliance roadmap
Honest current state and roadmap. Stickylink is an early-stage product, we won't claim certifications we don't have. If your procurement requires one of these before signing, email hello@stickylink.io and let us know which one, customer commitments help us prioritize.
| Framework | Status | Note |
|---|---|---|
| SOC 2 Type II | Planned | Targeting 2027 observation window once Workspace reaches ~25 paying orgs. |
| HIPAA / BAA | Planned | Requires SOC 2 + subprocessor BAAs (Supabase Enterprise). Not committed yet. |
| ISO 27001 | Not yet | Considered after SOC 2 if EU demand materializes. |
| PCI DSS | Not applicable | Payments are processed by Stripe; card data never touches our servers. |
| GDPR | In progress | Data-processing addendum available on request. hello@stickylink.io. |
| 21 CFR Part 11 (FDA) | Not yet | Requires validated e-signatures and system validation. Not a near-term target. |
| FedRAMP / IL2+ | Not yet | Multi-year process. Not on the roadmap. |
| HITRUST | Not yet | Only relevant once HIPAA lands. |
What we do have today
- • TLS 1.3 on all connections
- • At-rest encryption via Supabase (AWS-managed KMS)
- • Postgres row-level security on every workspace table
- • Domain-locked seat management
- • Append-only audit log with database-level trigger enforcement
- • Payments isolated to Stripe (no card data on our servers)
If something does go wrong, our incident response plan sets out severity levels, response times, 72-hour breach notification, and backup and recovery objectives.
Labs, research, and controlled technology
Stickylink is designed for the operational side of a lab: equipment checklists, calibration logs, sample custody travelers, SOP sign-offs, reagent inventory, and safety rounds. It is not designed to be an Electronic Lab Notebook (ELN), a LIMS, or a primary research-data repository.
- Pre-publication research data. Don't store raw experimental data, unpublished findings, novel methods, or patent-sensitive notebooks in Stickylink. A breach could compromise patent or publication timelines.
- Proprietary formulations and compositions. Store the operational identifier in Stickylink; keep the formulation master in your own controlled system.
- Export-controlled or government-funded research. Stickylink is not ITAR/EAR, FedRAMP, or DFARS-compliant. Do not use it for controlled technology, defense-related research, or projects with data-residency or citizenship restrictions.
- GLP, GMP, GxP, and 21 CFR Part 11. Stickylink does not provide validated e-signatures, system validation, or FDA-ready audit trails. Don't use it for clinical-trial records, batch records, or regulated quality systems that require 21 CFR Part 11.
The recommended pattern is the same as for manufacturing: keep the controlled master in your ELN/LIMS/ERP, and use Stickylink for the physical sticker-linked workflow on the floor.
How this roadmap was decided
This roadmap reflects the Stickylink team's current internal plan, not an independent audit or a customer commitment. Timelines and priorities are based on the typical order early-stage SaaS products pursue these frameworks (SOC 2 first because it unlocks most B2B procurement; HIPAA/HITRUST only after that because they require SOC 2 plus signed BAAs with our subprocessors; ISO 27001 driven by EU demand; FedRAMP and 21 CFR Part 11 are multi-year efforts we haven't committed to). If a specific framework is a hard requirement for your organization, email hello@stickylink.io and we will confirm what we can and cannot support in writing before you sign.
This page is maintained by the Stickylink team and updated as the roadmap evolves. It is app-owner editable content, not an independent attestation.
