US privacy posture
OnTrackio is an EU-built platform that serves US customers with US data residency, CCPA-aware tooling, and compliance evidence in SOC 2 vocabulary. This page is the honest summary of what that means today: what is live in the product, what is drafted paper, and what is intentionally not claimed.
- This page is an explanation, not a contract. US commercial terms are covered by the US addendum to the MSA and the CCPA Service Provider Addendum, both available from sales as drafts pending attorney execution.
- OnTrackio holds no SOC 2 or ISO 27001 attestation today. The current certification state, including target dates, lives on the certifications page and does not change based on which market you buy from.
Data residency
Every workspace is pinned to a home region at creation. US workspaces run in
AWS us-east-1; workspace data is not replicated to the EU or anywhere else.
The full model, including what stays global (billing and the slug registry)
and what never leaves the region (your database, documents, and backups), is
on the data residency page.
CCPA
For CCPA purposes the customer is the business and OnTrackio is a service provider. Concretely:
- No sale, no sharing. OnTrackio does not sell or share personal information, does not run advertising, and processes workspace data only to provide the service. This is certified contractually in the CCPA Service Provider Addendum.
- Consumer requests on the 45-day clock. The privacy request intake and the admin DSAR workflow are jurisdiction-aware: a US workspace gets the CCPA request types (know, delete, correct, opt out) and deadlines are computed on the CCPA's 45-day window rather than the GDPR's 30 days.
- The data is workforce inventory data. The platform processes employee directory profiles, device assignments, and software usage attribution. The endpoint agent's exact collection list is public in the agent documentation; it does not read keystrokes, window titles, or file contents.
SOC 2 vocabulary
The compliance hub renders in your jurisdiction's vocabulary. US workspaces see the identity-led view: asset and access evidence mapped to the Trust Services Criteria (CC3, CC6, CC7, CC8, CC9) via the built-in crosswalk, plus the exportable SOC 2 CC6 logical-access evidence pack generated from live workspace data. The same underlying evidence renders as NIS2 Article 21 controls for EU workspaces; the engine is one and the same.
As everywhere in the product: this is audit evidence, not certification. Generating the pack does not make anyone SOC 2 compliant; your auditor and your control environment do that.
What we deliberately do not claim
- HIPAA. Out of scope by decision. The platform does not touch PHI, and no BAA is offered.
- FedRAMP / government frameworks. Not offered; government orders need a separate conversation.
- "CCPA certified." No such certification exists, so nobody should sell you one.