Compliance at RecordX
Framework status at a glance
| Framework | Status | What we do today |
|---|---|---|
| SOC 2 | Not certified. On roadmap. | We follow SOC 2 Common Criteria controls (access control, change management, monitoring, incident response). Underlying AWS platform is SOC 2 Type II attested. |
| GDPR | Aligned | Data stored in the EU. Data subject rights (access, rectification, erasure, portability) supported through the app and support channel. No sale of personal data. No AI training on user content. |
| HIPAA | Not certified. BAA available on request for scoped engagements. | Encryption at rest and in transit, access controls, audit logs. RecordX is not currently offered as a HIPAA-compliant Covered Entity or Business Associate by default; contact legal@recordx.io before recording PHI. |
| Israeli Privacy Protection Law, 5741-1981 | Governing law | RecordX operates under Israeli privacy law. Access, correction, and deletion rights under §13, §14, and the 2017 Information Security Regulations are honored. |
| CCPA (California) | Aligned | Right to know, right to delete, right to opt out of sale. We do not sell personal data. |
| ISO 27001 | Not certified. On roadmap. | We follow ISMS principles. Our cloud provider is ISO 27001 / 27017 / 27018 certified for the underlying platform. |
How we think about compliance
RecordX is a young company. We would rather tell you exactly where we stand than paste a wall of logos we did not earn. The truthful picture:
- The security controls that certifications audit are in place: encryption in transit and at rest, managed identity, least-privilege access, environment isolation, code review, vulnerability scanning, and audit logging.
- Independent third-party audits that turn those controls into a signed report are on the roadmap and not yet complete.
- Where a framework is contractually needed (a BAA for HIPAA scope, an EU DPA under GDPR), reach out and we will scope it with you.
Sub-processors and vendors
- AWS (Frankfurt,
eu-central-1) - hosting, storage, managed identity, KMS. - Meeting-bot provider - used only when you ask RecordX to send a bot to a Google Meet, Zoom, Teams, or Webex call, under a data processing agreement.
- Payment processors (Creem, Google Play, PayPal) - used only for billing; RecordX does not store card numbers.
A full sub-processor list is available on request. See the privacy policy for exact data-handling terms.
What buyers usually ask for
- Security controls summary and questionnaire response - available on request from security@recordx.io.
- Data Processing Agreement (GDPR Article 28) - available on request.
- Business Associate Agreement (HIPAA) - available for scoped engagements, contact legal@recordx.io.
- Penetration test summary and vulnerability management overview - available under NDA.
Contact us for a security review
Email security@recordx.io for compliance questions, controls documentation, or to start a procurement review. For legal agreements (DPA, BAA), email legal@recordx.io. We respond within two business days.
Related reading: Security overview, GDPR, SOC 2, HIPAA, Privacy Policy.