StampRight
Trust · Compliance

Built for the way
regulated work works.

Where we are today, what we sign, and what's on the audit roadmap. Honest status only — no fake certifications.

HIPAA BAA available

Hash-only architecture is structurally HIPAA-defensive. BAAs signed for Enterprise customers with healthcare use cases. Full certification on the Q4 2026 roadmap. Read the honest details →

GDPR + CCPA Live

Hash-only architecture limits PII surface by design. Full rights program (access, rectify, erase, port). DPA available on request. SCCs for cross-border transfers. See Privacy Policy.

eIDAS 2.0 2026

EU eIDAS 2.0 qualified-timestamp profile on the roadmap. Critical for EU regulated industries where qualified timestamps carry equivalent legal weight to handwritten signatures under EU law.

C2PA Content Credentials 2026

StampRight receipts will emit C2PA Content Credentials manifests, interoperable with Adobe, Microsoft, Sony, Nikon, and the broader provenance ecosystem. Especially important for photographers and journalists.

SOC 2 Type II Q1 2027

Audit window opens Q3 2026. Type II report issued Q1 2027. The five Trust Services Criteria — Security, Availability, Confidentiality, Processing Integrity, Privacy — across an extended observation period.

Post-quantum signature ready Live

Receipts carry markers for post-quantum signature migration. When NIST-mandated quantum-safe signatures arrive, your existing stamps upgrade without rebreaking the chain.

Transparency

The full subprocessor list.

Every third-party service that touches Customer Data, what it does, and where it's located.

Subprocessor Purpose Region
DigitalOceanInfrastructure hostingUS (NYC3)
DigitalOcean Managed PostgresDatabaseUS (NYC3)
ClerkAuthentication / identityUS
ResendTransactional email (default)US
Postmark / AWS SESTransactional email (HIPAA tenants)US
StripePayments processingUS

We notify Enterprise customers in writing 30 days before adding or replacing any subprocessor that handles Customer Data.

Security disclosure

Found a vulnerability?

We take responsible disclosure seriously. Report any security issue to security@stampright.com — we acknowledge within 48 hours and patch within 7 days for high-severity issues.

Enterprise compliance questions?

Custom DPAs, BAAs, SCCs, and security questionnaires welcome.

Talk to compliance Read HIPAA posture