Purpose of this page
Organizations use Compliance Locker to store sensitive documents with client-side encryption and to generate activity records that support internal governance, security review, and audit workflows. This page explains platform capabilities. It does not state or imply that Compliance Locker, by itself, makes you compliant with any law, regulation, or industry standard.
Immutable audit ledger
The Service records vault-related events in an insert-only audit ledger. Supported action types include UPLOAD, VIEW, SHARE, and DELETE. Each entry typically contains:
- UTC timestamp
- Action type
- File reference identifier
- Hashed file identifier for long-term reference
- Pseudonymized actor identifier
- Pseudonymized network identifier
Audit rows are designed to remain even if the underlying file record is deleted, so deletion itself creates a traceable event without erasing historical ledger entries.
Authenticated vault owners can filter, review, and export audit data in CSV or JSON format for internal records.
Compliance certificates
The application can generate per-document certificates summarizing available cryptographic metadata and related audit history for files you own. Certificates are intended to support internal attestations and should be validated within your own compliance workflow. They are not a substitute for formal regulatory filings, third-party audit opinions, or legal certifications.
Framework mapping (informational only)
Customers often evaluate whether product controls can support obligations under frameworks such as SOC 2, ISO/IEC 27001, HIPAA, GDPR, or sector-specific rules. Whether Compliance Locker is appropriate for a given framework depends on your data types, policies, contracts, hosting configuration, workforce practices, and overall control environment.
HIPAA: Use of protected health information generally requires appropriate administrative, physical, and technical safeguards, workforce training, risk analysis, and often a business associate agreement where applicable. Encryption and audit logging may support security objectives but do not, alone, create HIPAA compliance. Compliance Locker does not provide medical advice and does not act as your covered entity or business associate unless expressly agreed in a separate written contract.
SOC 2 / ISO 27001: Access controls, encryption, and logging may map to common control themes. Formal SOC 2 Type I/II reports or ISO certifications, if available, would be provided only under separate enterprise arrangements and are not offered by default through the standard Service.
GDPR / privacy laws: Data protection obligations depend on your role as controller or processor, lawful basis, notices, data subject rights, transfers, and subprocessors. See our Privacy Policy.
Shared responsibility
Secure and compliant use requires shared responsibility:
- Compliance Locker: platform architecture, encryption design, access enforcement on the service side, and audit record generation
- Customer: data classification, access approvals, user training, incident response, retention schedules, vendor review, contracts, and legal interpretation
Data location and retention
Processing and storage regions depend on deployment configuration and subprocessors used for hosting, database, and object storage. See our subprocessor list page for provider details. Confirm regions with your administrator. Retention of encrypted files, account metadata, and audit logs is described in our Privacy Policy and your internal policies.
No legal or compliance warranty
Compliance Locker makes no representation that use of the Service will satisfy any specific legal, regulatory, accreditation, or contractual requirement. You should consult qualified legal and compliance professionals before relying on the Service for regulated data or high-risk processing.
The information on this page is provided for general informational purposes only and does not constitute legal, regulatory, or professional advice. You are responsible for determining whether the Service meets your compliance obligations.