How Canny Technologies handles regulatory requirements โ HIPAA, GDPR, SOC 2, PCI-DSS, RBI, and India's DPDP Act โ across industries and geographies.
Health Insurance Portability and Accountability Act โ US federal law governing Protected Health Information (PHI) security and privacy.
General Data Protection Regulation โ EU law governing the collection, storage, and processing of personal data of EU/UK residents.
AICPA Service Organisation Control 2 โ audit standard covering security, availability, processing integrity, confidentiality, and privacy.
Payment Card Industry Data Security Standard โ mandatory security standard for any system that stores, processes, or transmits cardholder data.
Reserve Bank of India digital lending, data localisation, and IT security guidelines for banks, NBFCs, and payment aggregators.
Digital Personal Data Protection Act 2023 โ India's first comprehensive data protection law governing personal data processing for Indian residents.
Canny Technologies is not itself a HIPAA-covered entity, PCI-DSS merchant, or SOC 2 certified organisation. We act as a technical implementation partner that builds compliance into client systems. For systems requiring formal certification, we build the controls that enable your organisation to achieve and maintain certification. Our own SOC 2 Type II audit is currently in progress. Contact us for our most current compliance documentation.
Tell us your regulatory context and we'll outline exactly how we'd address it in your project architecture.
Discuss Your Requirements