FugokuFugoku Docs
Mask

Compliance & Certifications

SOC 2 Type II, ISO 27001, PCI DSS, GDPR, data residency, and regulatory compliance details

Compliance & Certifications

Fugoku maintains industry-standard security certifications and regulatory compliance to help you meet your own compliance obligations.

Current Certifications

SOC 2 Type II

Status: Certified

Scope: Security, Availability, Confidentiality

Audit frequency: Annual

Report availability: Request SOC 2 report: compliance@fugoku.com (requires NDA)

Trust services criteria:

  • Security: Firewall rules, encryption, access controls, MFA
  • Availability: 99.9% SLA, redundant infrastructure, disaster recovery
  • Confidentiality: Tenant isolation, data encryption, access logging

ISO 27001

Status: Certified

Scope: Information Security Management System (ISMS)

Audit frequency: Annual

Certification body: an accredited registrar

Key controls:

  • Risk assessment and treatment
  • Access control and identity management
  • Incident management and business continuity
  • Supplier relationships and third-party management

PCI DSS Level 1

Status: Certified

Scope: Payment card processing infrastructure

Audit frequency: Annual

Shared responsibility model:

  • Fugoku provides: Secure infrastructure, network isolation, encryption, tokenization
  • You provide: Secure application code, PCI-compliant configuration, cardholder data protection

Compliance assistance:

  • Pre-configured PCI-compliant instance templates
  • Network segmentation guides
  • Quarterly vulnerability scans

Regional Compliance

Lagos, Nigeria (lagos-1)

  • NDPR (Nigeria Data Protection Regulation) — Active
  • ISO 27001 — Certified
  • Data residency: Customer data stored in Nigeria

Frankfurt, Germany (frankfurt-1)

  • GDPR — Compliant
  • ISO 27001 — Certified
  • SOC 2 Type II — Certified
  • Data residency: Customer data stored in Germany

London, UK (london-1)

  • GDPR — Coming with launch
  • UK Data Protection Act — Coming with launch
  • ISO 27001 — Planned
  • Status: Coming Soon

Ashburn, USA (ashburn-1)

  • SOC 2 — Planned
  • HIPAA — Ready for healthcare workloads
  • Data residency: Customer data stored in USA
  • Status: Coming Soon

Data Residency Guarantee

  • Data never leaves the region you select unless you explicitly configure replication
  • Cross-region replication is opt-in only
  • Regional compliance is enforced at the infrastructure level
  • Audit logs are available for all data access and movement

GDPR Compliance Tools

Right to Erasure

# Delete all customer data
fugoku account delete --confirm --erase-all-data
# All instances, volumes, snapshots, backups permanently deleted within 24 hours

Data Export

# Export all account data (GDPR data portability)
fugoku account export --format json --output my-data.json
# Includes: instances, volumes, audit logs, billing records

Data Processing Addendum (DPA)

Available in Console → Account → Legal → Sign DPA

Security Certifications Roadmap

CertificationTarget DateStatus
SOC 3Q4 2026In progress
ISO 27017Q1 2027Planned
ISO 27018Q1 2027Planned
HIPAAQ2 2027Planned
FedRAMPQ3 2027Evaluating

Compliance Documentation

Available upon request:

  • SOC 2 Type II report (requires NDA)
  • ISO 27001 certificate
  • PCI DSS Attestation of Compliance
  • GDPR Data Processing Agreement
  • Penetration test summary (redacted)
  • Security questionnaire responses

Contact compliance@fugoku.com for documentation requests.

Audit & Assessment

  • Annual third-party audit: SOC 2, ISO 27001, PCI DSS
  • Quarterly penetration testing: External security firm
  • Continuous monitoring: Automated vulnerability scanning, compliance drift detection
  • Incident response: 24/7 security on-call, P1 response < 15 minutes

Regulatory Compliance by Industry

Financial Services

  • SOC 2 Type II (Security, Availability, Confidentiality)
  • PCI DSS Level 1 for payment processing
  • GDPR for EU customer data
  • NDPR for Nigerian customer data

Healthcare

  • HIPAA-ready infrastructure (coming Q2 2027)
  • SOC 2 for data security
  • GDPR for EU patient data
  • Data residency guarantees

Government

  • FedRAMP evaluation (coming Q3 2027)
  • SOC 2 for federal workloads
  • Data residency and sovereignty options

Third-Party Assessments

  • Security audits: Annual third-party penetration test and vulnerability assessment
  • Compliance audits: Annual SOC 2 and ISO 27001 audits by accredited firms
  • Bug bounty: Public bug bounty program (coming Q4 2026)
  • Responsible disclosure: security@fugoku.com

Next Steps:

On this page