Compliance
LogVault is designed to help B2B SaaS companies meet strict compliance requirements. Here's how we help you pass audits.
SOC 2 Type II
SOC 2 requires demonstrating that your systems have appropriate security controls. LogVault helps with:
| Trust Principle | How LogVault Helps |
|---|---|
| Security | Immutable audit trail, encryption at rest (AES-256), TLS 1.3 in transit |
| Availability | 99.99% SLA, automatic failover, EU-hosted infrastructure |
| Processing Integrity | Cryptographic signatures, chain verification, tamper detection |
| Confidentiality | Automatic PII scrubbing, data isolation per organization |
| Privacy | GDPR-compliant data handling, retention policies, export tools |
GDPR
The General Data Protection Regulation requires specific data handling practices:
- Data Minimization (Art. 5) - Our PII scrubbing ensures you only store necessary data
- Right to Access (Art. 15) - Export all events for a specific user
- Right to Erasure (Art. 17) - Delete user data on request
- Data Portability (Art. 20) - Export in JSON or CSV format
- EU Data Residency - All data stored in Frankfurt (eu-central-1)
DPA Available
We provide a standard Data Processing Agreement (DPA) that covers all GDPR requirements. Download DPA
HIPAA
For healthcare applications handling Protected Health Information (PHI):
- Access Controls - API key authentication, organization isolation
- Audit Controls - Complete audit trail of all access
- Integrity Controls - Cryptographic signatures prevent tampering
- Transmission Security - TLS 1.3 encryption for all communications
Note: HIPAA compliance requires a Business Associate Agreement (BAA). Contact us at legal@logvault.eu to request one.
ISO 27001
LogVault's infrastructure providers (Supabase, Railway) maintain ISO 27001 certification. Our practices align with:
- A.12.4 - Logging and monitoring
- A.14.1 - Security requirements of information systems
- A.18.1 - Compliance with legal and contractual requirements
Compliance Reports
Generate compliance reports for your auditors directly from the dashboard:
- Event Summary - Total events, unique actors, action distribution
- Integrity Report - Chain verification results, cryptographic proofs
- Access Report - Who accessed what data and when
- Retention Report - Data lifecycle and deletion records
Security Certifications
LogVault inherits security certifications from our infrastructure providers:
| Provider | Certifications |
|---|---|
| Supabase (Database) | SOC 2 Type II, HIPAA, ISO 27001 |
| Railway (API) | SOC 2 Type II |
| Vercel (Frontend) | SOC 2 Type II, ISO 27001 |
Need Help?
If you're preparing for an audit and need specific documentation or assistance, contact our team:
- Security questions: security@logvault.eu
- Legal/DPA requests: legal@logvault.eu
- Security page: logvault.app/security