20xwork is an early company and we say plainly where we are.
| Framework | Status |
|---|---|
| SOC 2 Type II | Audit period open; report expected in 2027. A bridge letter describing current controls is available under NDA. |
| ISO 27001 | Controls aligned; certification planned after SOC 2. |
| GDPR | DPA with Standard Contractual Clauses, EU hosting available, DPIA template on request. |
| HIPAA | Not offered. 20xwork does not process protected health information. |
We complete customer security questionnaires (SIG, CAIQ, or your own) and share our penetration test summary and policies under NDA. Email adharsh@20xwork.ai.