Compliance
The rules you operate under — and what we actually hold.
India-first, globally minded. Privacy, data protection and tax are engineered in — and we state plainly which certifications are still on the roadmap.
DPDP & GDPRBy design
GST invoicing Live
SOC 2 / ISO 27001Not yet certified
Regulatory posture
India DPDP Act
Consent, data-subject rights and lawful processing built for India’s Digital Personal Data Protection Act.
By designEU GDPR
The same rights model — access, erasure, portability — extends to GDPR as we expand into the EU.
By designData residency
Tenant data is isolated and, as we grow, region-pinnable for enterprise and EU customers.
ConfigurableRetention & erasure
Configurable retention and a right-to-erasure cascade with export; guest data is minimized by default.
ConfigurableGST invoicing
Compliant GST invoices with UPI, cards and net-banking — arriving with billing launch.
At billing launchSubprocessors
A transparent, current list with notice of changes — available on request under a DPA.
On requestCertifications & attestations
SOC 2 Type II
Not yet certified. Our controls are designed to align with the criteria; a formal audit is on the roadmap.
Not yet certifiedISO 27001
Not yet certified. A roadmap item as we scale enterprise deployments.
Not yet certifiedDPA
A data processing agreement is available on request for enterprise due diligence.
On requestNo solely-automated harm
Consequential decisions stay human-owned. A guest decline, a listing takedown, an account lock — HostOS recommends with a reason; a person decides. It mirrors the legal standard and is a product principle, not a checkbox.