Everything your legal and security teams will ask for

Buying compliance software means a diligence review. This page exists to make that review short: what documentation exists, how to get it, and straight answers to the questions that normally take three email rounds.

Documentation

Available security and compliance documentation
Document Status How to get it
ISO 27001 certificate Held On request
SOC 2 report Held On request, under NDA
Privacy notice Published Read it now
Sub-processor list Published Read it now
Accessibility statement Published Read it now
Data Processing Agreement In preparation Ask and we will tell you where it stands
Security questionnaire response Completed on request Send us yours

Where the Data Processing Agreement stands. The privacy notice establishes that your organisation is the data fiduciary for case, survey, training and attendance records and that we process them on your instructions — a relationship that requires a DPA. Ours is being drafted with counsel. We would rather say that than send you a template we have not had reviewed.

The questions procurement actually asks

Where does our data live?
In India. Production runs in the AWS Mumbai region, and an automated check fails the build if a non-Indian region is ever configured — so residency is enforced rather than promised.
Can our HR team see an employee’s harassment complaint?
No. Only the Internal Committee can open a PoSH case. HR, Compliance and the Data Protection Officer cannot, and that boundary is enforced in the database rather than in application code.
Is our data used to train AI models?
No. EECly contains no artificial-intelligence feature at all, so nothing an employee writes is sent to an AI provider.
Who is the data fiduciary — you or us?
It depends on the record, and the privacy notice sets out each one. For harassment, whistleblower, grievance, survey, training and attendance data the employer is the fiduciary and we process on your instructions. For employee wellbeing data we are the fiduciary and answer to the employee directly.
What happens to data when we leave?
Wellbeing and counselling data is destroyed irreversibly. Statutory records are retained because the law obliges you to hold them, and a legal hold pauses deletion while a case is open. We will walk the exit path with you before you sign, not after.

Reporting a security issue

If you have found a vulnerability, tell us at legal@annotatory.com and we will work with you on it. We do not pursue legal action against good-faith research. Our machine-readable contact is published at /.well-known/security.txt.