Skip to main content
Trust & Compliance

Compliance & Certifications

How Canny Technologies handles regulatory requirements โ€” HIPAA, GDPR, SOC 2, PCI-DSS, RBI, and India's DPDP Act โ€” across industries and geographies.

Compliance Commitments at a Glance

NDA before project discussionAlways
IP assignment to clientAlways
BAA for HIPAA projectsAlways
DPA for GDPR projectsAlways
Data residency documentationAlways
Annual pen test (Canny infrastructure)Annual
Project pen test for regulated industriesPer project
Dependency vulnerability scanningEvery build
Compliance checklist sign-off before launchEvery project
Post-launch security monitoringContinuous

Regulatory Framework Coverage

๐Ÿ‡บ๐Ÿ‡ธ
HIPAA
United States ยท Healthcare
20+ HIPAA-compliant platforms delivered

Health Insurance Portability and Accountability Act โ€” US federal law governing Protected Health Information (PHI) security and privacy.

  • Business Associate Agreements (BAA) signed before any PHI exposure
  • Technical safeguards: AES-256 encryption at rest and in transit
  • Access controls with unique user IDs, auto logoff, MFA
  • Immutable audit logs for all PHI access and modifications
  • HIPAA-eligible AWS services only (BAA in scope)
  • Third-party pen test before launch for all healthcare platforms
๐Ÿ‡ช๐Ÿ‡บ
GDPR
European Union / UK ยท All industries
15+ GDPR-compliant platforms for EU/UK clients

General Data Protection Regulation โ€” EU law governing the collection, storage, and processing of personal data of EU/UK residents.

  • Data Processing Agreements (DPA) for EU/UK clients
  • Lawful basis assessment for each data processing activity
  • Privacy by design: minimal data collection, purpose limitation
  • Right-to-erasure implementation (soft delete + hard purge workflow)
  • Data residency in EU regions (AWS eu-west-1, eu-central-1)
  • Cookie consent management integration (OneTrust or custom)
๐ŸŒ
SOC 2 Type II
Global (SaaS standard) ยท SaaS / B2B Tech
10+ SOC 2-readiness engagements completed

AICPA Service Organisation Control 2 โ€” audit standard covering security, availability, processing integrity, confidentiality, and privacy.

  • Controls mapped to SOC 2 Trust Service Criteria at project outset
  • Logging and monitoring aligned to CC7 (System Operations) requirements
  • Change management process aligned to CC8 (Change Management)
  • Risk assessment documentation for each client system
  • Third-party audit readiness support for clients undergoing SOC 2
  • Formal Canny Technologies SOC 2 Type II audit in progress (2025)
๐Ÿ’ณ
PCI-DSS
Global ยท Payments / E-Commerce
25+ PCI-compliant payment integrations

Payment Card Industry Data Security Standard โ€” mandatory security standard for any system that stores, processes, or transmits cardholder data.

  • Never store raw card data โ€” tokenisation via Stripe or Razorpay only
  • PCI-DSS scope minimisation: cardholder data environment isolated
  • HTTPS/TLS 1.3 enforced on all payment-adjacent endpoints
  • Network segmentation: payment services in dedicated VPC subnets
  • Third-party PCI ASV scan before production payment launches
  • Quarterly vulnerability scans on payment system infrastructure
๐Ÿ‡ฎ๐Ÿ‡ณ
RBI / NBFC Guidelines
India ยท Banking / Lending
12+ RBI-compliant FinTech platforms

Reserve Bank of India digital lending, data localisation, and IT security guidelines for banks, NBFCs, and payment aggregators.

  • Data localisation: all Indian customer financial data stored in India (AWS ap-south-1)
  • RBI digital lending guidelines: disbursement/collection only to/from verified bank accounts
  • Account Aggregator framework integration (NBFC clients)
  • Aadhaar OTP and video-based KYC implementation
  • NACH mandate management via approved payment gateways
  • Regulatory reporting capability (CRILC, SMA classification)
๐Ÿ‡ฎ๐Ÿ‡ณ
DPDP Act
India ยท All industries (India)
All new India projects DPDP-compliant by design

Digital Personal Data Protection Act 2023 โ€” India's first comprehensive data protection law governing personal data processing for Indian residents.

  • Consent management system for all personal data collection
  • Data fiduciary obligations: purpose limitation, data minimisation
  • Data Principal rights: access, correction, erasure, grievance redressal
  • Data localisation for sensitive personal data categories
  • Significant Data Fiduciary (SDF) compliance assessment for large-scale platforms
  • Breach notification workflow: 72-hour notification to DPBI as required

Compliance Transparency Note

Canny Technologies is not itself a HIPAA-covered entity, PCI-DSS merchant, or SOC 2 certified organisation. We act as a technical implementation partner that builds compliance into client systems. For systems requiring formal certification, we build the controls that enable your organisation to achieve and maintain certification. Our own SOC 2 Type II audit is currently in progress. Contact us for our most current compliance documentation.

Have a Specific Compliance Requirement?

Tell us your regulatory context and we'll outline exactly how we'd address it in your project architecture.

Discuss Your Requirements