Compliance & Certifications
SOC 2 Type II, ISO 27001, PCI DSS, GDPR, data residency, and regulatory compliance details
Compliance & Certifications
Fugoku maintains industry-standard security certifications and regulatory compliance to help you meet your own compliance obligations.
Current Certifications
SOC 2 Type II
Status: Certified
Scope: Security, Availability, Confidentiality
Audit frequency: Annual
Report availability: Request SOC 2 report: compliance@fugoku.com (requires NDA)
Trust services criteria:
- Security: Firewall rules, encryption, access controls, MFA
- Availability: 99.9% SLA, redundant infrastructure, disaster recovery
- Confidentiality: Tenant isolation, data encryption, access logging
ISO 27001
Status: Certified
Scope: Information Security Management System (ISMS)
Audit frequency: Annual
Certification body: an accredited registrar
Key controls:
- Risk assessment and treatment
- Access control and identity management
- Incident management and business continuity
- Supplier relationships and third-party management
PCI DSS Level 1
Status: Certified
Scope: Payment card processing infrastructure
Audit frequency: Annual
Shared responsibility model:
- Fugoku provides: Secure infrastructure, network isolation, encryption, tokenization
- You provide: Secure application code, PCI-compliant configuration, cardholder data protection
Compliance assistance:
- Pre-configured PCI-compliant instance templates
- Network segmentation guides
- Quarterly vulnerability scans
Regional Compliance
Lagos, Nigeria (lagos-1)
- NDPR (Nigeria Data Protection Regulation) — Active
- ISO 27001 — Certified
- Data residency: Customer data stored in Nigeria
Frankfurt, Germany (frankfurt-1)
- GDPR — Compliant
- ISO 27001 — Certified
- SOC 2 Type II — Certified
- Data residency: Customer data stored in Germany
London, UK (london-1)
- GDPR — Coming with launch
- UK Data Protection Act — Coming with launch
- ISO 27001 — Planned
- Status: Coming Soon
Ashburn, USA (ashburn-1)
- SOC 2 — Planned
- HIPAA — Ready for healthcare workloads
- Data residency: Customer data stored in USA
- Status: Coming Soon
Data Residency Guarantee
- Data never leaves the region you select unless you explicitly configure replication
- Cross-region replication is opt-in only
- Regional compliance is enforced at the infrastructure level
- Audit logs are available for all data access and movement
GDPR Compliance Tools
Right to Erasure
# Delete all customer data
fugoku account delete --confirm --erase-all-data
# All instances, volumes, snapshots, backups permanently deleted within 24 hoursData Export
# Export all account data (GDPR data portability)
fugoku account export --format json --output my-data.json
# Includes: instances, volumes, audit logs, billing recordsData Processing Addendum (DPA)
Available in Console → Account → Legal → Sign DPA
Security Certifications Roadmap
| Certification | Target Date | Status |
|---|---|---|
| SOC 3 | Q4 2026 | In progress |
| ISO 27017 | Q1 2027 | Planned |
| ISO 27018 | Q1 2027 | Planned |
| HIPAA | Q2 2027 | Planned |
| FedRAMP | Q3 2027 | Evaluating |
Compliance Documentation
Available upon request:
- SOC 2 Type II report (requires NDA)
- ISO 27001 certificate
- PCI DSS Attestation of Compliance
- GDPR Data Processing Agreement
- Penetration test summary (redacted)
- Security questionnaire responses
Contact compliance@fugoku.com for documentation requests.
Audit & Assessment
- Annual third-party audit: SOC 2, ISO 27001, PCI DSS
- Quarterly penetration testing: External security firm
- Continuous monitoring: Automated vulnerability scanning, compliance drift detection
- Incident response: 24/7 security on-call, P1 response < 15 minutes
Regulatory Compliance by Industry
Financial Services
- SOC 2 Type II (Security, Availability, Confidentiality)
- PCI DSS Level 1 for payment processing
- GDPR for EU customer data
- NDPR for Nigerian customer data
Healthcare
- HIPAA-ready infrastructure (coming Q2 2027)
- SOC 2 for data security
- GDPR for EU patient data
- Data residency guarantees
Government
- FedRAMP evaluation (coming Q3 2027)
- SOC 2 for federal workloads
- Data residency and sovereignty options
Third-Party Assessments
- Security audits: Annual third-party penetration test and vulnerability assessment
- Compliance audits: Annual SOC 2 and ISO 27001 audits by accredited firms
- Bug bounty: Public bug bounty program (coming Q4 2026)
- Responsible disclosure: security@fugoku.com
Next Steps: