HyperLocal
Security & Compliance

Compliance is not a gate.It is the floor.

Every app built or migrated with HyperLocal is born compliant. Classify the workload — HIPAA, SOC 2, PCI-DSS, GDPR — and the right encryption, logging, deployment pattern, and network controls activate automatically. Security is not bolted on. It is the operating model.

Security & Governance Posture
Defence in depth · Enforced by design
GovernancePolicy · Audit · Evidence
Policy Enforcement
Network & RBAC rules
AUTOMATED
Audit Export
SOC 2 · ISO 27001
IMMUTABLE LOGS
Drift Detection
Baseline enforcement
MINUTES
Compliance Frameworks
SOC2 · GDPR · HIPAA
CONTINUOUS
Operations Agent
CVE patching · Cert rotation
ALWAYS-ON
enforces
Control Plane — Zero TrustRBAC · Secrets · Verify always
Zero-Trust Ops
No implicit trust
VERIFY ALWAYS
RBAC & Least Privilege
Role-enforced access
CC6.2 · CC6.3
Secrets Management
Auto cert rotation
CC6.1 · CC6.6
Vulnerability Patching
Continuous CVE scan
AUTO-REMEDIATED
Observability & SLA
Health · Uptime evidence
A1.1 · A1.2
manages
Customer Data PlaneYour infra · Your keys
Kubernetes
Customer-owned
Network Policies
Namespace isolation
Purpose-fit DBs
Data residency
App Runtimes
Open-source
ForgeAgent
Local execution
Encryption Keys
Customer-managed
"Compliance is not a gate — it is the floor."
Security Posture

Built-in governance controls

Zero-trust operational model
Every action through the control plane is authenticated, authorised, and logged. Least-privilege access enforced at the agent layer — no persistent admin credentials in the data plane.
Drift detection & mitigation
Continuous comparison of running state against declared policy baseline. Deviations flagged immediately, auto-remediated or queued for operator review.
Backup intent & retention
Centralised backup policies define schedule, retention windows, and encryption requirements. Evidence of execution retained for audit.
Observability & audit trail
All control-plane operations produce immutable audit records. Health signals centralised without moving application data out of customer environments.
Secrets & certificate management
Auto-rotation of certificates and secrets for runtime and infrastructure. Vault scoped per customer environment — no plaintext credentials at rest.
Operations Agent — always on
Automated CVE patching, certificate rotation before expiry, anomaly detection, and predictive failure analysis. Continuous, not on a vendor release cycle.
Born Compliant

Classify the workload. The compliance posture follows automatically.

When you classify a workload as HIPAA, PCI-DSS, or SOC 2, the entire stack inherits the right posture — encryption standards, audit logging, deployment patterns, and network boundaries. No manual configuration. No missed controls. The app is born compliant, not made compliant after the fact.

Example: HIPAA-classified workload
Automatic
FIPS 140-2 encryption
KMS-managed keys with FIPS 140-2 Level 2 validation. Encryption at rest and in transit — automatically applied.
Immutable audit logs
Every data access, mutation, and admin action logged to tamper-proof storage. Retention per compliance requirement.
TLS everywhere
Mutual TLS between services, TLS 1.3 at the edge, certificate auto-rotation via Operations Agent.
Observability auto-aggregated
Logs, metrics, and traces automatically routed to the central observability platform. No per-app setup.
Pre-approved deployment
Deployed via approved Argo-based patterns in pre-validated IaC templates — onto existing cluster or new infra.
Network isolation
Namespace isolation, network policies, ingress controls, egress filtering — inherited from the compliance template.

The same model works for PCI-DSS, SOC 2, GDPR, NIS2, and DORA. Each compliance classification activates the right controls — encryption standards, log retention, network boundaries, deployment patterns, and audit evidence collection.

Compliance Frameworks

Continuous evidence. Automated controls.

SOC 2 Type II
Security · Availability · Confidentiality

Continuous evidence collection — access logs, change records, availability metrics, encryption attestation. Audit preparation reduced from weeks to a single export.

Automated by HyperLocal
Continuous control evidence
Access + change audit logs
Availability SLA monitoring
Encryption attestation
ISO 27001
Information Security Management

Policy intent encoded at the control plane, enforced on every data plane. Risk controls, asset inventories, and treatment records maintained programmatically.

Automated by HyperLocal
Policy-as-code enforcement
Automated risk control records
Asset inventory from infra state
Drift detection against baselines
GDPR
Data Residency · Privacy · Erasure

Customer data never enters the control plane. Data residency enforced per-region by design. Configurable retention, customer-managed keys, erasure workflow support.

Automated by HyperLocal
Per-region data residency
Customer-managed encryption keys
Configurable data retention
Right-to-erasure workflow hooks
HIPAA
Healthcare · PHI Isolation

PHI remains in customer-owned VPCs and never traverses the control plane. FIPS 140-2 encryption, network segmentation, access logging, and encrypted storage enforced automatically.

Automated by HyperLocal
PHI isolation in customer VPCs
FIPS 140-2 Level 2 encryption
Full access + activity logging
BAA-compatible architecture
Always-on controls

Active from the moment infrastructure is provisioned. No opt-in. No per-app config.

TLS 1.2+ enforced on all connections
Secrets stored in customer-scoped vaults
Network policies applied to every namespace
Immutable audit trail for all operations
Automated certificate rotation
Vulnerability scanning on runtime images
Backup encryption with customer-managed keys
RBAC aligned to least-privilege by default
Data sovereignty by design

Customer data never enters the HyperLocal control plane. It stays inside the customer's own VPC or datacenter. The control plane issues intent; execution happens locally via ForgeAgent.

For air-gapped environments, ForgeAgent operates from locally cached policy state without a persistent outbound connection.

What crosses the API
Configuration intent and policy state
Telemetry metadata (no payload data)
Health checks and availability signals

See compliance in action

We'll walk through your compliance requirements and show how workload classification activates the right controls automatically — encryption, logging, deployment, and audit evidence.