Security & Compliance
What we actually build — and what we don't claim.
Most boilerplate security pages either say nothing specific or overclaim a certification no codebase can hold. Here’s the honest version: what SOC 2 and ISO 27001 actually certify, why a starter kit can’t hold either one, and exactly which real controls in this codebase satisfy which framework clause.
What we don’t claim
SOC 2, ISO 27001, and ISO 42001 certify an operating organization over time — an evidence window, personnel, incident-response drills, management review, and an accredited third-party auditor. No codebase, boilerplate, or starter kit can be “SOC 2 certified” in any meaningful sense, and we won’t tell you otherwise. If a vendor claims their template is SOC 2 or ISO 27001 certified, ask what auditor issued the report — there isn’t one, because there can’t be.
What we do build — and what it’s worth to you
The technical controls those frameworks actually require, correctly implemented from day one, so your compliance work — when you run this as a real product under your own company — starts from a real foundation instead of a retrofit.
| Control area | Included in | Framework relevance |
|---|---|---|
| Audit logging — every state-changing action tracked, tamper-evident | ENTERPRISE | SOC 2 CC7, ISO 27001 A.8.15, DPDP/GDPR accountability |
| Role-based access control, least-privilege by design | All tiers | SOC 2 CC6, ISO 27001 A.5.15–18 |
| MFA — TOTP, SMS, WebAuthn/Passkeys | ENTERPRISE | SOC 2 CC6.1, ISO 27001 A.8.5 |
| Field-level PII encryption, HSTS, CSP, rate limiting | All tiers | SOC 2 CC6.6–7, ISO 27001 A.8.24 |
| GDPR/DPDP data-subject rights — export, deletion, consent capture with history | All tiers | GDPR Art. 15/17/20, DPDP Act 2023 |
| Breach-notification tooling — log incidents, mark affected users, notify | ENTERPRISE | GDPR Art. 33/34 |
| Cookie consent management with audit trail | All tiers | GDPR/DPDP consent requirements |
| Tokenized billing — Stripe/Razorpay hosted fields, no card data touches your servers | All tiers | PCI DSS — architecture eligible for the lightest SAQ-A scope |
| Structured logging, health checks, backup-friendly Docker setup | All tiers | SOC 2 availability criteria, ISO 27001 A.8.13–14 |
None of this makes you certified either — you still need your own policies, your own evidence window, and your own auditor if you’re pursuing SOC 2 or ISO 27001 as an operating business. What it means: the technical half of that work — usually the most expensive and error-prone half — is already done, tested, and battle-hardened, instead of something you bolt on under audit pressure six months before your first customer asks for a SOC 2 report.
No AI-governance claims (EU AI Act, ISO 42001, NIST AI RMF): this template has no AI/generative features, so those frameworks don’t apply. If you add AI features on top of this foundation, that governance work is yours to scope separately.
Questions people actually ask
Is RAMSIO SaaS Starter SOC 2 or ISO 27001 certified?
No, and no boilerplate can be. SOC 2 and ISO 27001 certify an operating organization over time — an evidence window, personnel, incident-response drills, management review, and an accredited third-party auditor. A codebase you buy once cannot hold a certification like that; only the company running it as a live product, over time, can. If a vendor tells you their template is "SOC 2 certified," ask which auditor issued the report — there isn’t one, because there can’t be.
So what's actually true about RAMSIO's security posture?
The technical controls those frameworks require are correctly implemented from day one — audit logging, RBAC, MFA, field-level encryption, rate limiting, GDPR/DPDP data-subject rights, and more. The table above maps each one to the specific clause it satisfies. When you run this as a real product under your own company, your compliance work starts from a real foundation instead of a retrofit — but you still need your own policies, your own evidence window, and your own auditor if you pursue certification.
Does this cover AI governance frameworks (EU AI Act, ISO 42001, NIST AI RMF)?
No — this template has no AI or generative features, so those frameworks don’t apply to it. If you add AI features on top of this foundation, that governance work is yours to scope separately.