Compliance roadmap
Honest current state and roadmap. Stickylink is an early-stage product, we won't claim certifications we don't have. If your procurement requires one of these before signing, email hello@stickylink.io and let us know which one, customer commitments help us prioritize.
| Framework | Status | Note |
|---|---|---|
| SOC 2 Type II | Planned | Targeting 2027 observation window once Workspace reaches ~25 paying orgs. |
| HIPAA / BAA | Planned | Requires SOC 2 + subprocessor BAAs (Supabase Enterprise). Not committed yet. |
| ISO 27001 | Not yet | Considered after SOC 2 if EU demand materializes. |
| PCI DSS | Not applicable | Payments are processed by Stripe; card data never touches our servers. |
| GDPR | In progress | Data-processing addendum available on request. hello@stickylink.io. |
| 21 CFR Part 11 (FDA) | Not yet | Requires validated e-signatures and system validation. Not a near-term target. |
| FedRAMP / IL2+ | Not yet | Multi-year process. Not on the roadmap. |
| HITRUST | Not yet | Only relevant once HIPAA lands. |
What we do have today
- • TLS 1.3 on all connections
- • At-rest encryption via Supabase (AWS-managed KMS)
- • Postgres row-level security on every workspace table
- • Domain-locked seat management
- • Append-only audit log with database-level trigger enforcement
- • Payments isolated to Stripe (no card data on our servers)
How this roadmap was decided
This roadmap reflects the Stickylink team's current internal plan, not an independent audit or a customer commitment. Timelines and priorities are based on the typical order early-stage SaaS products pursue these frameworks (SOC 2 first because it unlocks most B2B procurement; HIPAA/HITRUST only after that because they require SOC 2 plus signed BAAs with our subprocessors; ISO 27001 driven by EU demand; FedRAMP and 21 CFR Part 11 are multi-year efforts we haven't committed to). If a specific framework is a hard requirement for your organization, email hello@stickylink.io and we will confirm what we can and cannot support in writing before you sign.
This page is maintained by the Stickylink team and updated as the roadmap evolves. It is app-owner editable content, not an independent attestation.
