Compliance
Last Updated: July 25, 2026
This page sets out our compliance posture: which regulations apply to us, what we have in place today, and what we are working towards.
We would rather tell you plainly where we are than imply certifications we do not hold.
Index
- Certification Status
- Data Protection Regulations
- AI Regulation
- Biometric Regulation
- Security Practices
- Payment Compliance
- Accessibility
- Documentation Requests
- Vendor Questionnaires
1. Certification Status
We do not currently hold SOC 2 or ISO 27001 certification.
We operate security controls consistent with those frameworks, described in our Security Policy, and we intend to pursue formal certification as the business grows. We will update this page when that changes.
If your procurement process requires a current certification report, tell us early so we can discuss what evidence we can provide instead.
2. Data Protection Regulations
| Regulation | Our position | | --- | --- | | India — Digital Personal Data Protection Act, 2023 | We are an Indian entity and act as Data Fiduciary. We operate consent-based processing, publish retention periods, and have a designated Grievance Officer. | | EU / UK GDPR | We act as controller for our own users and processor for enterprise customers. We support data subject rights, offer a Data Processing Addendum, and use recognized transfer safeguards. | | California — CCPA / CPRA | We do not sell personal information or share it for cross-context behavioural advertising. We honour access, deletion, and correction requests. | | Other US state privacy laws | We treat biometric data as sensitive personal information requiring opt-in consent, consistent with Colorado, Connecticut, and comparable laws. |
Our detailed practices are in our Privacy Policy.
3. AI Regulation
AI-specific regulation is developing quickly, and we track it rather than waiting to be caught out.
- EU AI Act. Our Services are general-purpose creative tools. We prohibit the uses the Act classifies as unacceptable or high-risk, including social scoring, biometric categorization for surveillance, emotion inference, predictive policing, and automated decisions affecting legal rights. Those prohibitions are in our Acceptable Use Policy.
- Transparency obligations. We embed provenance metadata and apply watermarks where the output format supports it, and we require users not to remove them.
- Synthetic media disclosure. Users publishing synthetic depictions of people are responsible for the labelling their jurisdiction requires. We state this in our Terms and our AI Services Disclosure.
Our broader commitments are set out in our Responsible AI Policy.
4. Biometric Regulation
Avatar and voice features process facial geometry and voiceprints, which several laws regulate specifically.
We operate to the requirements of the Illinois Biometric Information Privacy Act as a baseline, since it is the most demanding of the regimes that apply to our users: written consent before collection, a published retention schedule with a three-year outer limit, no sale or profit from biometric data, and a protective standard of care.
Full detail is in our Biometric Data Policy. Enterprise customers supplying biometric data about their own end users are responsible for obtaining the required consents, as set out in our Enterprise Terms.
5. Security Practices
Our controls cover encryption in transit and at rest, least-privilege access with periodic review, audit logging, security monitoring, dependency and vulnerability management, encrypted backups, and a defined incident response process including regulatory breach notification.
These are described in our Security Policy, which also sets out our responsible disclosure process and safe harbour for researchers.
6. Payment Compliance
Payment card data is handled entirely by our payment provider, which acts as merchant of record and maintains its own PCI DSS compliance. We do not receive, process, or store complete card numbers, which keeps card data out of our environment.
7. Accessibility
We build against WCAG 2.1 Level AA as our target standard and treat accessibility defects as bugs rather than enhancements.
We have not completed a formal third-party audit. If you encounter a barrier, report it to support@inferon.ai and we will prioritize it.
8. Documentation Requests
On request, and subject to a confidentiality agreement where appropriate, we can provide:
- Our Data Processing Addendum, ready for execution — see Data Processing Addendum
- Our current subprocessor list and change notifications — see Subprocessors
- Documentation of our international transfer mechanisms
- A summary of our security architecture and data flows
- Our incident response and breach notification process
- Retention and deletion schedules
Contact privacy@inferon.ai for data protection documentation, legal@inferon.ai for contractual matters, or security@inferon.ai for security-specific material.
9. Vendor Questionnaires
We complete reasonable security and privacy questionnaires as part of enterprise procurement.
To keep this efficient, please send the questionnaire in an editable format, tell us your deadline, and flag any question that is a hard requirement so we can address it first. Where an answer is "not yet", we will say so rather than answer around it.
Penetration testing against our production environment requires written permission and an agreed scope and window. Contact security@inferon.ai.