Trust Center

Our commitment to security, privacy, and transparent data practices.

1. How We Handle Your Data

At GRAP Solutions, trust is our core operating principle. We work under standard enterprise security requirements:

2. Compliance and Certification Status

We believe in absolute transparency about where we stand regarding formal certifications:

Framework Status Notes
GDPR Aligned Data minimization, strict retention, and DPAs executed on all contracts.
HIPAA Aligned Workflows BAAs available on request for healthcare/medical data projects.
SOC 2 Type II Audit In Progress Formal audit cycle currently underway with external auditors.
ISO/IEC 27001 Not Yet In Place Processes and policies are aligned; formal audit planned.

3. Authorized Subprocessors

To deliver our secure annotation, translation, and collection platforms, GRAP Solutions works with the following subprocessors:

Entity Name Service Description Data Location
Amazon Web Services, Inc. Cloud hosting infrastructure, databases, and secure workspaces US / EU / India (Configured per contract)
Google Cloud Platform Auxiliary compute, backup hosting, and client deliverables transfer US / EU / India (Configured per contract)
Formspree, Inc. Contact form transmission and processing United States

4. Data Residency Options

Enterprise clients can specify geographic region restrictions for datasets under annotation. We support isolated data storage and workspace compute environments restricted to EU-only, US-only, or India-only availability zones, preventing egress across geographic boundaries.

5. Contact Security Group

For DPO inquiries, data access requests, or to review our complete written security policies, please contact our team at production@grap-solutions.com.