A finance system touches every billing line in your business. We built InstantViewAI to the standard your auditors will eventually hold it to — read-only cloud access, isolated tenants, KMS envelope encryption, EU/US data residency, and an immutable audit trail by default. SOC 2 Type II audit underway.
InstantViewAI never needs write access to your cloud accounts. Read-only billing, inventory, and utilization access is enough — and it means a worst-case incident on our side cannot start, stop, or change anything in your environment. Period.
No agents to install. No write permissions. The total ask on your side is roughly 2 – 3 hours of your team's time in week 1, then about 30 minutes a week thereafter.
We're explicit about which certifications are in place, which are in progress, and when the report will land. No "compliance theater."
| Standard | Status | Target / report date | Notes |
|---|---|---|---|
| SOC 2 Type II | In audit | Report expected Q3 2026 | Type I completed; Type II observation period underway with Big-4 auditor. |
| GDPR | Aligned | In place | DPA available. EU-first architecture. Designated EU Data Protection contact. |
| ISO 27001 | Planned | Readiness Q4 2026 · cert Q2 2027 | Following SOC 2 audit. ISMS framework in build. |
| CSA STAR Level 1 | Self-assessed | Submitted | Cloud Security Alliance CAIQ available on request. |
| Penetration test | Annual | Last: Q1 2026 · next: Q1 2027 | Independent firm. Executive summary available under NDA. |
| Provider | Purpose | Data | Region |
|---|---|---|---|
| Google Cloud Platform | Hosting, compute, BigQuery, KMS | All customer data | EU (europe-west4) / US (us-central1) |
| Keycloak (self-hosted on GCP) | Identity & SSO | User identity | EU / US |
| Mailjet | Transactional email + scheduled reports | Email, attachments | EU (France) |
| Sentry | Error monitoring | Application errors (no customer PII) | EU |
30-day advance notice for any subprocessor change. Subscribe via the trust portal — contact security@instantview.ai.
We run a coordinated disclosure programme. Submit findings to security@instantview.ai — PGP key on the site. We acknowledge within 48 hours, triage within 5 working days, and pay bounties on a published severity scale.
SOC 2 audit-progress letter, CAIQ, pen-test summary, DPA, subprocessor list, and security questionnaire responses — bundled and sent within one business day.