CapchaCloud 20 control themes — strong security practices and transparency. We do not guarantee legal or regulatory outcomes.
Each item links to a dedicated page. Deeper evidence packets and runbooks are shared through procurement when appropriate.
Also: Why CapchaCloud · Roadmap (public product direction) · Status & probes
Operator: Service Automations LLC · Effective May 15, 2026 · Single contact: support@serviceautomations.ai
Guidance for reviewing visitor-consent workflows is available to signed-in operators. Not legal advice.
How we describe controls alongside common frameworks—without claiming certification.
What we operate vs. what you configure (domains, keys, BYOB, webhooks).
Binding processor terms + SCC references. Start with DPA summary for orientation.
Who we rely on and how we notify material changes.
Data classes and lifecycle—in principle and by configuration.
How preservation requests work alongside deletion.
Operational records designed to make later alteration detectable.
TLS, platform crypto, BYOB; CMK roadmap.
Severity model and customer communication principles.
How we drill breaches and outages—cadence and scope.
Access reviews and production change discipline.
Phishing-resistant MFA and break-glass expectations.
Known-good settings, drift reduction, infrastructure-as-code.
Disclosure intake and remediation targets.
Dependencies, provenance, CycloneDX artifacts in CI.
Gates: review, scans, secrets hygiene, release discipline.
Third-party testing cadence and remediation tracking.
Regional processing information and the roadmap for tenant controls.
PR checklist: minimization, purpose, sensitive fields.
How we assemble audit artifacts—controls, logs, policies, exports.
Operate with counsel for jurisdictional requirements. Contact: serviceautomations.ai.