Developer portal
Compliance program
Selected internal checklists summarized for security review — full markdown lives in the repository.
Last updated: 2026-06-09
Overview
Program artifacts
SOC 2 Type I kickoff
Pre-observation checklist mapping Qtangl controls (RLS, audit log, key lifecycle) to CC-series evidence.
Repository path:
View on GitHub →docs/compliance/soc2-type1-kickoff.mdPenetration test scope
TH-001 SSRF/live-scan scope, metadata IP blocks, and remediation ticket linkage for external testers.
Repository path:
View on GitHub →docs/compliance/pen-test-scope.mdLegal review checklist
DPA/MSA/BAA review items, subprocessors, and marketing claim guardrails before enterprise contracts.
Repository path:
View on GitHub →docs/compliance/legal-review-checklist.mdRemediation audit sampling
Sampling methodology for remediation evidence during SOC 2 observation.
Repository path:
View on GitHub →docs/compliance/remediation-audit-sampling.mdSOC 2 sensor controls
Host sensor control mapping for enterprise discovery pilots.
Repository path:
View on GitHub →docs/compliance/soc2-sensor-controls.mdDiscovery pen test scope
Optional sensor/binary discovery scope for external testers.
Repository path:
View on GitHub →docs/compliance/discovery-pen-test-scope.mdEmployee security policy
v0.1 founder-signed policy for SOC 2 observation prep.
Repository path:
View on GitHub →docs/compliance/employee-security-policy.mdPlatform backup runbook
Postgres backup, evidence retention, and quarterly restore drill checklist.
Repository path:
View on GitHub →docs/ops/platform-backup-restore-runbook.mdQuestionnaire drafts
CAIQ Lite, SIG Lite, and top-20 FAQ for enterprise turnaround.
Repository path:
View on GitHub →docs/compliance/questionnaires/security-questionnaire-faq.mdContracts & insurance checklist
Cyber insurance, vendor DPAs, and procurement artifacts required for regulated customers.
Repository path:
View on GitHub →docs/compliance/contracts-insurance-checklist.md
Request packaged evidence
Enterprise customers may request CAIQ/SIG questionnaire responses, architecture summaries, and testing statements under NDA via /access. See also Legal artifacts.
Found an issue? Report documentation feedback