Book a Demo

Home / Trust / Compliance

Compliance

Appice operates under the certifications, regulations, and frameworks that matter to our customers — banks, insurers, healthcare, telcos, and government across India, GCC, and EU.

Certification status

StandardStatusScopeEvidence
SOC 2 Type IIIn progressSecurity, Availability, ConfidentialityQ2 2026 target. Type I report available now under NDA.
ISO/IEC 27001:2022PlannedISMS for production environmentsGap assessment Q3 2026; certification target Q4 2026.
ISO/IEC 27701PlannedPrivacy extension to 27001Bundled with 27001 certification track.
GDPR (EU)CompliantProcessor obligations under Art. 28DPA, Standard Contractual Clauses, DPO appointed.
India DPDP Act 2023CompliantData fiduciary and processor rolesIndia-resident infrastructure; consent and grievance flows.
HIPAA (US)BAA availableHealthcare customersBusiness Associate Agreement signed on request.
RBI Cybersecurity FrameworkAlignedBanks under RBI jurisdictionDeployed at 10+ Tier-1 Indian banks.
SAMA Cybersecurity Framework (KSA)AlignedSaudi banksGCC region deployment; data resident in Saudi Arabia.
PCI-DSSOut of scopeAppice does not store, process, or transmit cardholder data.

How we run the program

Compliance at Appice is owned by a dedicated Information Security team reporting to the CTO. The program is built on three loops:

Customer questionnaires and due diligence

Standard responses to common security questionnaires (CAIQ, SIG, VSAQ) are maintained and refreshed quarterly. We can typically complete custom questionnaires within 5 business days. Email security@appice.ai with your form attached.

Sector-specific commitments

Banking and financial services

Healthcare

Government

Need an evidence pack? SOC 2 Type I report, latest pen-test summary, and ISO 27001 readiness statement are available under NDA. Contact security@appice.ai.

Related