Compliance

The rules you operate under — and what we actually hold.

India-first, globally minded. Privacy, data protection and tax are engineered in — and we state plainly which certifications are still on the roadmap.

DPDP & GDPRBy design
GST invoicing Live
SOC 2 / ISO 27001Not yet certified
Regulatory posture
India DPDP Act
Consent, data-subject rights and lawful processing built for India’s Digital Personal Data Protection Act.
By design
EU GDPR
The same rights model — access, erasure, portability — extends to GDPR as we expand into the EU.
By design
Data residency
Tenant data is isolated and, as we grow, region-pinnable for enterprise and EU customers.
Configurable
Retention & erasure
Configurable retention and a right-to-erasure cascade with export; guest data is minimized by default.
Configurable
GST invoicing
Compliant GST invoices with UPI, cards and net-banking — arriving with billing launch.
At billing launch
Subprocessors
A transparent, current list with notice of changes — available on request under a DPA.
On request
Certifications & attestations
SOC 2 Type II
Not yet certified. Our controls are designed to align with the criteria; a formal audit is on the roadmap.
Not yet certified
ISO 27001
Not yet certified. A roadmap item as we scale enterprise deployments.
Not yet certified
DPA
A data processing agreement is available on request for enterprise due diligence.
On request
No solely-automated harm

Consequential decisions stay human-owned. A guest decline, a listing takedown, an account lock — HostOS recommends with a reason; a person decides. It mirrors the legal standard and is a product principle, not a checkbox.

Due diligence

Need our DPA or subprocessor list?