Compliance at RecordX

Framework status at a glance

Framework Status What we do today
SOC 2 Not certified. On roadmap. We follow SOC 2 Common Criteria controls (access control, change management, monitoring, incident response). Underlying AWS platform is SOC 2 Type II attested.
GDPR Aligned Data stored in the EU. Data subject rights (access, rectification, erasure, portability) supported through the app and support channel. No sale of personal data. No AI training on user content.
HIPAA Not certified. BAA available on request for scoped engagements. Encryption at rest and in transit, access controls, audit logs. RecordX is not currently offered as a HIPAA-compliant Covered Entity or Business Associate by default; contact legal@recordx.io before recording PHI.
Israeli Privacy Protection Law, 5741-1981 Governing law RecordX operates under Israeli privacy law. Access, correction, and deletion rights under §13, §14, and the 2017 Information Security Regulations are honored.
CCPA (California) Aligned Right to know, right to delete, right to opt out of sale. We do not sell personal data.
ISO 27001 Not certified. On roadmap. We follow ISMS principles. Our cloud provider is ISO 27001 / 27017 / 27018 certified for the underlying platform.

How we think about compliance

RecordX is a young company. We would rather tell you exactly where we stand than paste a wall of logos we did not earn. The truthful picture:

Sub-processors and vendors

A full sub-processor list is available on request. See the privacy policy for exact data-handling terms.

What buyers usually ask for

Contact us for a security review

Email security@recordx.io for compliance questions, controls documentation, or to start a procurement review. For legal agreements (DPA, BAA), email legal@recordx.io. We respond within two business days.

Related reading: Security overview, GDPR, SOC 2, HIPAA, Privacy Policy.

Try RecordX free