Skip to main content

Compliance posture

FrameworkEnclave statusNotes
SOC 2 Type II✓ CompliantReport available under NDA
ISO 27001✓ CertifiedCertificate available on request
GDPR✓ CompliantDPA available
HIPAA✓ BAA availableBusiness Associate Agreement on request
DPDP Act 2023✓ CompliantIndia data residency supported
IT Act 2000✓ Compliant
FedRAMPIn progress
Cyber Essentials✓ Certified

SOC 2 Type II

Enclave undergoes annual SOC 2 Type II audits covering:
  • Security — access controls, encryption, vulnerability management
  • Availability — uptime SLAs, incident response
  • Confidentiality — data classification, key management
The audit report is available to prospective and current customers under NDA. Contact hello@quelden.com to request a copy.

GDPR

Enclave’s zero-knowledge architecture directly supports GDPR obligations:
  • Data minimisation — Quelden processes only metadata, never plaintext content
  • Right of erasure — deleting a room destroys the KEK, permanently rendering all files unreadable
  • Data residency — EU-region deployments available; data does not leave your selected region
  • Sub-processors — full list available in the DPA
A Data Processing Agreement (DPA) is available at quelden.com/legal/dpa.

HIPAA

Enclave is HIPAA-eligible. For covered entities and business associates:
  • AES-256-GCM encryption satisfies the HIPAA Security Rule encryption standard
  • Audit logs satisfy access logging requirements (§164.312(b))
  • BYOK/HYOK ensures ePHI keys are controlled by the covered entity
  • A Business Associate Agreement (BAA) is available on request

Data residency

RegionAvailable
India (Mumbai)
EU (Frankfurt)
US East (Virginia)
US West (Oregon)
Singapore
Custom (private cloud)
Data stored in a region never leaves that region unless explicitly exported by an administrator.

Generating compliance reports

Enclave can generate compliance reports for internal use or auditor submission:
  1. Navigate to Reports → Compliance
  2. Select the framework (SOC 2, ISO 27001, GDPR, HIPAA, etc.)
  3. Set the reporting period
  4. Click Generate — the report is produced as a signed PDF
Reports include: access review results, permission changes, key management events, and an integrity verification of the underlying audit log.

Penetration testing

Enclave undergoes annual penetration tests by a CREST-accredited firm. Executive summaries are available to customers under NDA. Customers may also conduct their own penetration tests against their Enclave instance — notify security@quelden.com at least 5 business days in advance.