We will not claim a certification we have not earned.
Every serious evaluation of this product ends with a questionnaire, and the fastest way to fail one is to have implied something on a website that diligence then contradicts. So here is the position on each framework, including the parts where the answer is no, and the single control gap we consider most important.
The summary, before the detail
DMC Pilot holds no third-party security certification today. No SOC 2 report, no ISO 27001 certificate, no Cyber Essentials assessment. What exists is the set of technical controls those audits test: tenancy isolation enforced in the database, encryption of sensitive fields under a separate key, least-privilege permissions, an audit trail that survives account deletion, enforced retention and verified daily backups. All of it built while the product was built rather than retrofitted for an auditor.
The honest gap between those two sentences is process, contracts and elapsed time. A SOC 2 Type II cannot be written in code: it requires an auditor and months of observation. Below is what is done, what is not, and what each remaining item actually involves.
GDPR / UK GDPR
Partly in place
Substantially implemented; contractual work outstanding
We act as processor for the attendee and delegate data our customers hold, and as controller for our own account and website data. The technical obligations are built into the product. The contractual and documentary obligations are in progress.
In place
Data subject access and erasure tooling in the product
Configurable retention with enforced minimums and maximums
Special-category data encrypted at rest with a dedicated key
Health data reachable by the assistant only on a purpose-scoped request, and logged when it is
Audit trail preserved through erasure by pseudonymizing the actor rather than deleting the record
A subprocessor register compiled from the source code
An adopted incident response procedure committing to notify an affected customer within 48 hours, so they can meet their own 72-hour obligation
An enforced Article 9(2) condition: the platform refuses to store dietary or allergy data for a program until a named administrator has recorded the lawful basis, who collected the consent and where
A completed Data Protection Impact Assessment for special-category and staff-location processing, with a pre-filled template for the customer's own assessment
A completed transfer impact assessment covering every subprocessor under FISA 702, EO 12333 and the CLOUD Act
Outstanding
Executed Standard Contractual Clauses. The assessment supporting them is complete and the annexes are published; what remains is signature at onboarding
Appointment of an EU and a UK Article 27 representative. Required rather than optional: the operator is a Delaware company with no establishment in the EEA or the UK, and it offers the service to DMCs whose attendees are there. Two separate appointments; neither covers the other
Retention enforcement switched on: the schedule is built and runs in reporting mode until each customer opts in, so nothing is being deleted yet
CCPA / CPRA
Partly in place
Disclosures in place; we do not sell or share personal information
We do not sell personal information and do not share it for cross-context behavioral advertising, so no opt-out mechanism is required. The notice at collection and the sensitive-information limitation are set out in the Privacy Policy.
In place
Notice at collection covering every category we handle
No sale or sharing of personal information, and no behavioral advertising anywhere on the site or in the product
Access, deletion, correction and portability available through the product
Sensitive personal information used only to deliver the service, never inferred from or used to profile
Outstanding
Formal authorized-agent verification procedure
Annual privacy-training and request-metrics records
SOC 2 Type II
Not started
Not certified, and no audit has begun
SOC 2 Type II is an attestation by a licensed CPA firm that stated controls operated effectively across an observation window of typically three to twelve months. It cannot be achieved by writing software; it requires an auditor, a policy set, and elapsed time under observation. We have engaged neither an auditor nor started the observation period.
In place
Technical controls a SOC 2 audit would test: tenancy isolation, least-privilege access, encryption, audit logging, change management through version control
Automated daily database backups, verified as completing
Outstanding
Engage an audit firm and complete a readiness assessment
Adopt and evidence the full policy set
Independent penetration test
An independent off-site backup, held outside the database provider's own account
Complete the observation window
ISO/IEC 27001
Not started
Not certified, and no ISMS has been established
ISO 27001 certifies an Information Security Management System, not a product. It requires a defined scope, a risk assessment and treatment plan, a Statement of Applicability across the 93 Annex A controls, internal audit, management review, and a two-stage assessment by an accredited registrar.
In place
Cryptographic controls, access control and logging that map to Annex A 8.24, 8.3 and 8.15
Secure development practice: reviewed changes, dependency scanning, environment separation
Outstanding
Establish the ISMS, its scope and its risk treatment plan
Produce the Statement of Applicability
Internal audit and management review cycle
Stage 1 and Stage 2 assessment by an accredited registrar
Cyber Essentials
Partly in place
Not certified; the five technical controls are largely met
Cyber Essentials is a UK certification against five technical controls, assessed by an IASME-licensed body. It applies to the whole organization's IT, not only to the product, so certification depends on company devices and accounts as much as on this codebase.
In place
Firewalls and secure configuration: no self-managed servers, no inbound ports, platform-managed infrastructure
User access control: invite-only accounts, least-privilege permissions, TOTP two-factor authentication, single sign-on on Enterprise
Security update management: managed platforms patch themselves; application dependencies are scanned and updated
Malware protection: no user-supplied code executes, and uploads are stored rather than run
Outstanding
Assessment by an IASME-licensed certification body
Company-device policy, inventory and endpoint protection evidence
The gap we consider most important
There is no independent off-site backup yet.
The database platform takes automated daily backups and keeps seven days of them. We have verified those are completing. That part is real, and it is what would restore the service after a failure or a bad deployment.
What does not exist yet is a copy held outside that platform's own account. The mechanism is written and configured to write an encrypted dump to immutable object-lock storage for 35 days, but it is not yet running. Until it is, a scenario that takes the database account itself with it has no independent recovery path.
We are stating this because it is the item a competent auditor would raise first, it maps directly to a SOC 2 availability criterion and to ISO 27001 Annex A 8.13, and discovering it in diligence would reasonably make a buyer wonder what else we had not mentioned.
What we deliberately do not claim
Each of these is something a security page could easily imply. None of them is true of us today.
Any completed third-party audit, certification or attestation.
A published uptime service level agreement, or any availability percentage.
Point-in-time recovery. Restores are to a daily snapshot.
An independent penetration test.
EU or UK data residency. The platform runs in the United States.
Executed Standard Contractual Clauses, or a completed transfer impact assessment.
A formal, evidenced policy set of the kind SOC 2 and ISO 27001 require.
HIPAA compliance. We are not a covered entity and dietary data is not protected health information, though it is treated as special category data under the GDPR, which is stricter in several respects.
The documentation
Published in full rather than held back for diligence. A buyer's legal and security teams can read all of it before speaking to us.
Email security@dmcpilot.com. We acknowledge within two working days, keep you informed, and will not pursue action against research conducted in good faith under the terms in our disclosure policy and Acceptable Use Policy. Credit where you want it.
Send the questionnaire before you buy.
We would rather answer it now than be caught out by it later. Serious evaluations get the documentation, the architecture, and a call with the people who wrote it.