RAMSIO

Security & Compliance

What we actually build — and what we don't claim.

Most boilerplate security pages either say nothing specific or overclaim a certification no codebase can hold. Here’s the honest version: what SOC 2 and ISO 27001 actually certify, why a starter kit can’t hold either one, and exactly which real controls in this codebase satisfy which framework clause.

What we don’t claim

SOC 2, ISO 27001, and ISO 42001 certify an operating organization over time — an evidence window, personnel, incident-response drills, management review, and an accredited third-party auditor. No codebase, boilerplate, or starter kit can be “SOC 2 certified” in any meaningful sense, and we won’t tell you otherwise. If a vendor claims their template is SOC 2 or ISO 27001 certified, ask what auditor issued the report — there isn’t one, because there can’t be.

What we do build — and what it’s worth to you

The technical controls those frameworks actually require, correctly implemented from day one, so your compliance work — when you run this as a real product under your own company — starts from a real foundation instead of a retrofit.

Control areaIncluded inFramework relevance
Audit logging — every state-changing action tracked, tamper-evidentENTERPRISESOC 2 CC7, ISO 27001 A.8.15, DPDP/GDPR accountability
Role-based access control, least-privilege by designAll tiersSOC 2 CC6, ISO 27001 A.5.15–18
MFA — TOTP, SMS, WebAuthn/PasskeysENTERPRISESOC 2 CC6.1, ISO 27001 A.8.5
Field-level PII encryption, HSTS, CSP, rate limitingAll tiersSOC 2 CC6.6–7, ISO 27001 A.8.24
GDPR/DPDP data-subject rights — export, deletion, consent capture with historyAll tiersGDPR Art. 15/17/20, DPDP Act 2023
Breach-notification tooling — log incidents, mark affected users, notifyENTERPRISEGDPR Art. 33/34
Cookie consent management with audit trailAll tiersGDPR/DPDP consent requirements
Tokenized billing — Stripe/Razorpay hosted fields, no card data touches your serversAll tiersPCI DSS — architecture eligible for the lightest SAQ-A scope
Structured logging, health checks, backup-friendly Docker setupAll tiersSOC 2 availability criteria, ISO 27001 A.8.13–14

None of this makes you certified either — you still need your own policies, your own evidence window, and your own auditor if you’re pursuing SOC 2 or ISO 27001 as an operating business. What it means: the technical half of that work — usually the most expensive and error-prone half — is already done, tested, and battle-hardened, instead of something you bolt on under audit pressure six months before your first customer asks for a SOC 2 report.

No AI-governance claims (EU AI Act, ISO 42001, NIST AI RMF): this template has no AI/generative features, so those frameworks don’t apply. If you add AI features on top of this foundation, that governance work is yours to scope separately.

Questions people actually ask

Is RAMSIO SaaS Starter SOC 2 or ISO 27001 certified?

No, and no boilerplate can be. SOC 2 and ISO 27001 certify an operating organization over time — an evidence window, personnel, incident-response drills, management review, and an accredited third-party auditor. A codebase you buy once cannot hold a certification like that; only the company running it as a live product, over time, can. If a vendor tells you their template is "SOC 2 certified," ask which auditor issued the report — there isn’t one, because there can’t be.

So what's actually true about RAMSIO's security posture?

The technical controls those frameworks require are correctly implemented from day one — audit logging, RBAC, MFA, field-level encryption, rate limiting, GDPR/DPDP data-subject rights, and more. The table above maps each one to the specific clause it satisfies. When you run this as a real product under your own company, your compliance work starts from a real foundation instead of a retrofit — but you still need your own policies, your own evidence window, and your own auditor if you pursue certification.

Does this cover AI governance frameworks (EU AI Act, ISO 42001, NIST AI RMF)?

No — this template has no AI or generative features, so those frameworks don’t apply to it. If you add AI features on top of this foundation, that governance work is yours to scope separately.

See exactly which tier includes which control in the full feature comparison, the re-verified test/coverage numbers behind these claims on the status page, or how your data is handled in the Privacy Policy. Security questions specifically go to security@ramsio.tech.