We will not claim a certification we have not earned.

Every serious evaluation of this product ends with a questionnaire, and the fastest way to fail one is to have implied something on a website that diligence then contradicts. So here is the position on each framework, including the parts where the answer is no, and the single control gap we consider most important.

The summary, before the detail

DMC Pilot holds no third-party security certification today. No SOC 2 report, no ISO 27001 certificate, no Cyber Essentials assessment. What exists is the set of technical controls those audits test: tenancy isolation enforced in the database, encryption of sensitive fields under a separate key, least-privilege permissions, an audit trail that survives account deletion, enforced retention and verified daily backups. All of it built while the product was built rather than retrofitted for an auditor.

The honest gap between those two sentences is process, contracts and elapsed time. A SOC 2 Type II cannot be written in code: it requires an auditor and months of observation. Below is what is done, what is not, and what each remaining item actually involves.

GDPR / UK GDPR

Partly in place

Substantially implemented; contractual work outstanding

We act as processor for the attendee and delegate data our customers hold, and as controller for our own account and website data. The technical obligations are built into the product. The contractual and documentary obligations are in progress.

In place

  • Data subject access and erasure tooling in the product
  • Configurable retention with enforced minimums and maximums
  • Special-category data encrypted at rest with a dedicated key
  • Health data reachable by the assistant only on a purpose-scoped request, and logged when it is
  • Audit trail preserved through erasure by pseudonymizing the actor rather than deleting the record
  • A subprocessor register compiled from the source code
  • An adopted incident response procedure committing to notify an affected customer within 48 hours, so they can meet their own 72-hour obligation
  • An enforced Article 9(2) condition: the platform refuses to store dietary or allergy data for a program until a named administrator has recorded the lawful basis, who collected the consent and where
  • A completed Data Protection Impact Assessment for special-category and staff-location processing, with a pre-filled template for the customer's own assessment
  • A completed transfer impact assessment covering every subprocessor under FISA 702, EO 12333 and the CLOUD Act

Outstanding

  • Executed Standard Contractual Clauses. The assessment supporting them is complete and the annexes are published; what remains is signature at onboarding
  • Appointment of an EU and a UK Article 27 representative. Required rather than optional: the operator is a Delaware company with no establishment in the EEA or the UK, and it offers the service to DMCs whose attendees are there. Two separate appointments; neither covers the other
  • Retention enforcement switched on: the schedule is built and runs in reporting mode until each customer opts in, so nothing is being deleted yet

CCPA / CPRA

Partly in place

Disclosures in place; we do not sell or share personal information

We do not sell personal information and do not share it for cross-context behavioral advertising, so no opt-out mechanism is required. The notice at collection and the sensitive-information limitation are set out in the Privacy Policy.

In place

  • Notice at collection covering every category we handle
  • No sale or sharing of personal information, and no behavioral advertising anywhere on the site or in the product
  • Access, deletion, correction and portability available through the product
  • Sensitive personal information used only to deliver the service, never inferred from or used to profile

Outstanding

  • Formal authorized-agent verification procedure
  • Annual privacy-training and request-metrics records

SOC 2 Type II

Not started

Not certified, and no audit has begun

SOC 2 Type II is an attestation by a licensed CPA firm that stated controls operated effectively across an observation window of typically three to twelve months. It cannot be achieved by writing software; it requires an auditor, a policy set, and elapsed time under observation. We have engaged neither an auditor nor started the observation period.

In place

  • Technical controls a SOC 2 audit would test: tenancy isolation, least-privilege access, encryption, audit logging, change management through version control
  • Automated daily database backups, verified as completing

Outstanding

  • Engage an audit firm and complete a readiness assessment
  • Adopt and evidence the full policy set
  • Independent penetration test
  • An independent off-site backup, held outside the database provider's own account
  • Complete the observation window

ISO/IEC 27001

Not started

Not certified, and no ISMS has been established

ISO 27001 certifies an Information Security Management System, not a product. It requires a defined scope, a risk assessment and treatment plan, a Statement of Applicability across the 93 Annex A controls, internal audit, management review, and a two-stage assessment by an accredited registrar.

In place

  • Cryptographic controls, access control and logging that map to Annex A 8.24, 8.3 and 8.15
  • Secure development practice: reviewed changes, dependency scanning, environment separation

Outstanding

  • Establish the ISMS, its scope and its risk treatment plan
  • Produce the Statement of Applicability
  • Internal audit and management review cycle
  • Stage 1 and Stage 2 assessment by an accredited registrar

Cyber Essentials

Partly in place

Not certified; the five technical controls are largely met

Cyber Essentials is a UK certification against five technical controls, assessed by an IASME-licensed body. It applies to the whole organization's IT, not only to the product, so certification depends on company devices and accounts as much as on this codebase.

In place

  • Firewalls and secure configuration: no self-managed servers, no inbound ports, platform-managed infrastructure
  • User access control: invite-only accounts, least-privilege permissions, TOTP two-factor authentication, single sign-on on Enterprise
  • Security update management: managed platforms patch themselves; application dependencies are scanned and updated
  • Malware protection: no user-supplied code executes, and uploads are stored rather than run

Outstanding

  • Assessment by an IASME-licensed certification body
  • Company-device policy, inventory and endpoint protection evidence

The gap we consider most important

There is no independent off-site backup yet.

The database platform takes automated daily backups and keeps seven days of them. We have verified those are completing. That part is real, and it is what would restore the service after a failure or a bad deployment.

What does not exist yet is a copy held outside that platform's own account. The mechanism is written and configured to write an encrypted dump to immutable object-lock storage for 35 days, but it is not yet running. Until it is, a scenario that takes the database account itself with it has no independent recovery path.

We are stating this because it is the item a competent auditor would raise first, it maps directly to a SOC 2 availability criterion and to ISO 27001 Annex A 8.13, and discovering it in diligence would reasonably make a buyer wonder what else we had not mentioned.

What we deliberately do not claim

Each of these is something a security page could easily imply. None of them is true of us today.

  • Any completed third-party audit, certification or attestation.
  • A published uptime service level agreement, or any availability percentage.
  • Point-in-time recovery. Restores are to a daily snapshot.
  • An independent penetration test.
  • EU or UK data residency. The platform runs in the United States.
  • Executed Standard Contractual Clauses, or a completed transfer impact assessment.
  • A formal, evidenced policy set of the kind SOC 2 and ISO 27001 require.
  • HIPAA compliance. We are not a covered entity and dietary data is not protected health information, though it is treated as special category data under the GDPR, which is stricter in several respects.

Reporting a vulnerability

Email security@dmcpilot.com. We acknowledge within two working days, keep you informed, and will not pursue action against research conducted in good faith under the terms in our disclosure policy and Acceptable Use Policy. Credit where you want it.

Send the questionnaire before you buy.

We would rather answer it now than be caught out by it later. Serious evaluations get the documentation, the architecture, and a call with the people who wrote it.