/SLASHLOGIXX TRUST
Public Posture

Compliance & Frameworks

Last updated 2026-05-19

1. How We Think About Compliance

Procurement teams ask for compliance reports as a proxy for "is this vendor safe to plug in?" We answer that question directly. Where a framework genuinely improves security or genuinely changes a buyer's risk model, we map to it and produce evidence. Where a framework is purely a procurement checkbox, we make the actual controls visible enough that an informed reviewer can answer the underlying question without the badge.

The honest snapshot below shows what we map to today, what we provide on request, and what is explicitly out of scope for now.

2. Framework Posture

FrameworkPostureEvidence available
SOC 2 Type II Not pursuing a formal audit at this time SlashLogixx provides the underlying control evidence directly: this publicly readable trust-center policy set and a complete subprocessor list. See Section 4.
ISO 27001 Not pursuing a formal certification at this time Trust-center policies map to the Annex A control families relevant to a hosted SaaS.
HIPAA Eligible on signed BAA Customers handling PHI through Spark Cloud or Spark Connect may execute a BAA.
PCI DSS Not in scope (no card data stored) Card data is processed by our payment processor; SlashLogixx systems do not store primary account numbers. PCI scope is constrained to the processor's environment.
GDPR / UK GDPR Operating posture Privacy policy and the lawful-bases statement in the Privacy policy.
CCPA / CPRA Operating posture Rights-request workflow described in the Privacy policy. Contact privacy@slashlogixx.com.

3. Why No SOC 2 Today

A SOC 2 Type II audit is a structured representation that we are running a designed control set over a defined audit window. It is useful at a certain stage of company maturity and a certain price point. At SlashLogixx's current stage, the audit fee plus annual surveillance is not the most efficient way to give a procurement team confidence in our security posture.

Rather than route money to an auditor, we route it to the controls themselves: a publicly readable policy set and a complete, honest subprocessor list. This package gives most enterprise procurement teams more verifiable information than a SOC 2 cover page, faster, and at a lower implied cost to the buyer.

If your procurement team specifically requires a SOC 2 report and cannot accept the equivalent packet above, please write to security@slashlogixx.com. We will work with you to either find a contractual path forward or be transparent that we are not the right vendor for that requirement today.

4. The SOC 2 Equivalent Packet

The following bundle is available to any prospect or customer with a signed mutual NDA in place:

5. Customer-Side Compliance (Spark Connect & Connect BYOK)

On Spark Connect and Spark Connect BYOK, the customer operates its own VPC — and, on Connect BYOK, its own LLM endpoint and key — and is therefore the responsible party for any audit, certification, or framework attestation that applies to that infrastructure. SlashLogixx provides the software components and hosts the Spark control plane only, and is structurally outside the scope of customer-side SOC 2, ISO 27001, HIPAA, PCI, or similar audits of those customer-operated components. Customers running Spark Compliance (forthcoming) may use that app to streamline their own audit evidence collection.

6. Evidence Requests

To request any document referenced above, or to ask whether a specific control or framework is in scope for your evaluation: security@slashlogixx.com.