Skip to main content
Watch Taking a Sledgehammer to Bottlenecks 🎥 as Ruth & Steph show how AI actually fixes margins.

Compliance Standards

Compliance standards

GoSmarter runs on Microsoft Azure, which is certified against a broad set of compliance frameworks. This page maps the most commonly requested standards to our deployment.

Standards relevance

StandardRelevant?How GoSmarter aligns
GDPRYesAll GoSmarter-hosted persistent data in UK South. DPA available. Microsoft/Clerk/Stripe sub-processor DPAs apply automatically under each provider’s standard terms (Clerk and Stripe transfer to the US under DPF/SCCs — see Data Residency). No AI model training on customer data. See Privacy.
UK GDPR / Data Protection Act 2018YesUK South data residency. EU processing (Sweden Central) within adequacy framework. See Data Residency.
SOC 2 Type IIAzure platform certifiedAzure holds SOC 2 Type II. No current plans to attain this.
ISO 27001Azure platform certifiedAzure holds ISO 27001. Planning to attain GoSmarter application-level certification.
ISO 27017Azure platform certifiedCloud-specific security controls — covered by Azure certification.
ISO 27018Azure platform certifiedPII protection in cloud — covered by Azure certification.
Cyber Essentials PlusAzure platform certifiedUK government security scheme — Azure is certified. Planning to attain GoSmarter application-level certification.
PCI DSSNot applicableGoSmarter does not process, store, or transmit payment card data.
HIPAANot applicableGoSmarter does not process protected health information.
CCPALimited relevanceGoSmarter is B2B with minimal personal data. No California consumer data processing.

What “Azure platform certified” means

When we say Azure is certified, it means:

  • Microsoft has undergone independent third-party audits for the services GoSmarter uses (Azure SQL, Blob Storage, Container Apps, Key Vault, Service Bus, AI services)
  • Audit reports are available through the Microsoft Service Trust Portal
  • These certifications cover the infrastructure, physical security, and platform-level controls

GoSmarter’s application-level controls (authentication, tenant isolation, encryption configuration, AI data handling) are described throughout this trust centre and verified against our infrastructure code.

GDPR alignment summary

GDPR requirementGoSmarter implementation
Lawful basis for processingContractual necessity — processing to deliver the service
Data minimisationLimited personal data: user accounts, audit logs, and document contents
Storage limitationData retained for subscription duration, then 6 years post-termination (exportable throughout), consistent with common manufacturing quality/traceability record-keeping practice and UK limitation periods; earlier deletion on request
Data subject rightsAccess, rectification, erasure supported — see Privacy & Data Protection’s “Data subject rights” section for the full erasure process, including pseudonymised audit-trail retention and business-contact retention periods
Data protection by designEncryption at rest and in transit, managed identity, tenant isolation
International transfersUK/EU only for GoSmarter-hosted infrastructure. Clerk and Stripe (identity and billing sub-processors) transfer to the US under the Data Privacy Framework and Standard Contractual Clauses
Breach notificationFor confirmed personal data breaches, customer notification target is within 72 hours of confirmation. UK GDPR/ICO escalation is assessed and, where required, actioned within applicable statutory timelines.
Data Processing AgreementAvailable on request via support@gosmarter.ai
Sub-processor disclosureMicrosoft Azure (infrastructure), Clerk (authentication), and Stripe (billing) — each covered by its own standard DPA, applied automatically

Compliance matrix

For a detailed control-by-control mapping, see the compliance matrix (CSV).

Key points for your security team

  • GDPR / UK GDPR: Fully aligned: UK South residency, DPA available, no international transfers outside adequacy
  • SOC 2 / ISO 27001: Azure platform certified; GoSmarter has no current SOC 2 attestation plan and is planning application-level ISO 27001 certification
  • Incident response notification target: 72 hours for confirmed personal data breaches, with UK GDPR/ICO escalation criteria applied
  • Availability: Provided contractually based on your service agreement — see FAQ
  • PCI DSS / HIPAA: Not applicable: GoSmarter doesn’t handle payment or health data
  • Evidence available: Azure compliance reports via Service Trust Portal; GoSmarter-specific detail in this trust centre

Request evidence

Email us, contact us online, or book a compliance call.