Compliance roadmap

Honest current state and roadmap. Stickylink is an early-stage product, we won't claim certifications we don't have. If your procurement requires one of these before signing, email hello@stickylink.io and let us know which one, customer commitments help us prioritize.

The rule of thumb: if your data would fail a regulator's audit today, don't put it in Stickylink today. This is why the Workspace Terms prohibit PHI, PCI, ITAR, classified, and clinical-trial records.
FrameworkStatusNote
SOC 2 Type IIPlannedTargeting 2027 observation window once Workspace reaches ~25 paying orgs.
HIPAA / BAAPlannedRequires SOC 2 + subprocessor BAAs (Supabase Enterprise). Not committed yet.
ISO 27001Not yetConsidered after SOC 2 if EU demand materializes.
PCI DSSNot applicablePayments are processed by Stripe; card data never touches our servers.
GDPRIn progressData-processing addendum available on request. hello@stickylink.io.
21 CFR Part 11 (FDA)Not yetRequires validated e-signatures and system validation. Not a near-term target.
FedRAMP / IL2+Not yetMulti-year process. Not on the roadmap.
HITRUSTNot yetOnly relevant once HIPAA lands.

What we do have today

How this roadmap was decided

This roadmap reflects the Stickylink team's current internal plan, not an independent audit or a customer commitment. Timelines and priorities are based on the typical order early-stage SaaS products pursue these frameworks (SOC 2 first because it unlocks most B2B procurement; HIPAA/HITRUST only after that because they require SOC 2 plus signed BAAs with our subprocessors; ISO 27001 driven by EU demand; FedRAMP and 21 CFR Part 11 are multi-year efforts we haven't committed to). If a specific framework is a hard requirement for your organization, email hello@stickylink.io and we will confirm what we can and cannot support in writing before you sign.

This page is maintained by the Stickylink team and updated as the roadmap evolves. It is app-owner editable content, not an independent attestation.