The artifacts vendor-security teams ask for, in one place. Each section names the authoritative source and the current posture. Numbers and certificates link back to the canonical legal documents at /legal.
Status reported honestly — “in progress” means in progress, not aspirational.
Audit in progress with an independent CPA firm. No SOC 2 report has been issued yet — the Type I report is targeted for Q4 2026 and the Type II report for 2027. Our Letter of Engagement (evidence the audit is underway) is available under NDA.
Osyra is designing the Service to act as a processor for Customer Content. The pre-release DPA package covers the Standard Contractual Clauses and UK transfer terms, but must be reviewed and executed for each applicable customer before production processing begins. Self-serve data-subject-access and erasure tooling is still being delivered.
Designed-for, not yet delivered. Osyra is architected to emit Article-12 event records and to back Article 15(3) post-market monitoring and Annex IV technical-documentation obligations with signed inference receipts and capability attestations. The tenant-facing signed audit ledger and the EU-AI-Act compliance registry are still being wired end-to-end. Target compliance window: August 2026.
Program in progress. Osyra does not currently represent the pre-release service as HIPAA compliant, and a customer BAA is not available for execution today. PHI processing must remain disabled until the BAA package and the required technical and operational activation gates are complete for that customer.
Planned as out of scope. Osyra is designed not to store, process, or transmit primary account numbers; Stripe is the planned payment processor. This boundary must be validated before billing activation.
The pre-release DPA package is designed to incorporate the EU Standard Contractual Clauses and UK transfer terms where applicable. Request the current package for review; the executed customer agreement, not this summary, controls production processing.
5 providers are listed in the launch data-flow plan. Osyra has not launched a production service or placed production Customer Content with these providers. This register documents the engineering launch data-flow plan; every provider remains subject to security, privacy, and contract review before activation.
| Provider | Purpose | Region | Status |
|---|---|---|---|
| Amazon Web Services | Compute · storage · networking · KMS · audit-log retention | us-east-1, eu-west-1 | Planned for launch |
| Stripe | Payments · invoicing · subscriptions | United States (PCI DSS Level 1) | Planned for launch |
| Resend | Transactional email · verification · receipts · alerts | United States | Planned for launch |
| Plausible | Cookieless web analytics · public marketing site only | European Union | Planned for launch |
| Sentry | Error monitoring · performance traces | United States · EU data region available | Planned for launch |
Canonical register with data scope, activation boundary, and change history: /legal/subprocessors.
Vulnerability reports, coordinated disclosures, and incident questions go to the published security mailbox and machine-readable RFC 9116 record.
We are establishing a third-party penetration-testing programme on a planned quarterly cadence against the production estate — Edge Gateway, IAM, Billing, Model Broker, and the authenticated console. Findings will be remediated and re-tested before the next scheduled engagement; summary reports will be available under NDA on request as the programme matures.
At launch, Customers can opt in to email notifications whenever a new subprocessor is added or a listed provider's role materially changes. The planned process provides a 30-day notice window before activation and a documented objection path.