Legal & Compliance

Legal & Compliance Surfaces

Privacy, terms, security, compliance, acceptable use, cookies, data processing, and SLA. Eight legal surfaces that govern every Perception X2 engagement.

Built for transparency, auditability, and protection. SOC 2 Type II, ISO 27001, GDPR, CCPA, and defense-grade certifications — zero security incidents in 15+ years.

0
Legal Surfaces
0
Security Incidents
0.0000%
Uptime SLA
0+
Compliance Frameworks
0%
Global Privacy
Compliance Coverage

Eight Frameworks. Continuous Verification.

Coverage percentage and certification status across the eight compliance frameworks that govern the Perception X2 platform. All metrics verified by annual third-party audit.

SOC 2 Type IICERTIFIED100%
ISO 27001:2022CERTIFIED100%
GDPR (EU)COMPLIANT100%
CCPA (California)COMPLIANT100%
HIPAA (US)ELIGIBLE100%
PCI-DSSIN PROGRESS90%
FedRAMP ModerateIN PROGRESS85%
Defense-gradeCERTIFIED100%
Legal & Compliance Capabilities

What the Legal Stack Delivers

Eight foundational capabilities shared across every legal surface — each engineered to protect clients, ensure compliance, and maintain audit-grade lineage.

GDPR & CCPA Compliant

Full compliance with EU GDPR, California CCPA, and global privacy regulations. Privacy by design, privacy by default.

Defense-Grade Security

AES-256 encryption, TLS 1.3, zero trust architecture, SOC 2 Type II, ISO 27001 — zero incidents in 15+ years.

Audit-Grade Lineage

Every metric, decision, and data point traceable to its source. Full lineage capture for compliance and regulatory review.

Data Residency

Multi-region active-active with sovereign-grade data residency. GDPR-compliant data processing in EU, US, APAC.

Sub-Processor Disclosure

Transparent sub-processor list, regular updates, and right to object. Full Article 28 GDPR compliance.

Right to Erasure

Full GDPR Article 17 right to erasure. Verified data deletion across all systems within 30 days.

Cross-Border Transfers

Standard Contractual Clauses, Binding Corporate Rules, and adequacy decisions. Compliant cross-border data flows.

Contractual SLA

99.9999% uptime, sub-second stream latency, 24/7 incident response. Remedy credits on breach.

Legal Applications

Six Compliance Patterns

The Perception X2 legal stack supports six primary compliance and assurance patterns — from GDPR review to defense and sovereign engagement.

GDPR Compliance Review

Privacy by design verified against GDPR Article 25. Article 28 DPA in place. Cross-border transfer mechanisms documented and current.

SOC 2 Type II Audit

Annual SOC 2 Type II audit with continuous monitoring. Trust Service Criteria coverage across security, availability, and confidentiality.

ISO 27001 Certification

ISO/IEC 27001:2022 certified. Information Security Management System with documented controls and continuous improvement.

Defense & Sovereign Engagement

Sovereign-grade data residency with cryptographic isolation. Air-gapped on-premise deployment available for classified environments.

Regulatory Reporting

Audit-grade export for regulatory submissions. Full source lineage, timestamp preservation, and immutable evidence chain.

Vendor Risk Assessment

Pre-completed security questionnaires (CAIQ, SIG, custom). On-demand attestation reports and penetration test summaries.

SLA Response Tiers

Contractual Response & Resolution Targets

Four SLA tiers govern the Perception X2 platform. Response time is the maximum delay from incident report to first acknowledgement. Resolution time is the maximum delay from report to verified fix.

TierDescriptionResponseResolution
P0 · Critical
Platform-wide outage or material security incident.< 5 min< 60 min
P1 · High
Material feature degradation or limited outage.< 15 min< 4 hr
P2 · Standard
Standard functional issue with available workaround.< 1 hr< 24 hr
P3 · Low
Cosmetic issue or minor feature request.< 8 hr< 5 d
Why These Legal Surfaces

The Trust Differentiators That Compound

0

Zero Security Incidents

15+ years of operations without a single security breach. The same standards used by defense and intelligence agencies.

SOC 2 Type II

Annual SOC 2 Type II audit with continuous monitoring. All five Trust Service Criteria covered with documented controls.

ISO 27001 Certified

ISO/IEC 27001:2022 certified Information Security Management System. Documented controls and continuous improvement.

GDPR Compliant

Full Article 28 DPA, Article 17 right to erasure, Article 30 records of processing, Article 32 security of processing.

99.9999%

99.9999% Uptime

Contractual SLA with remedy credits. Multi-region active-active with sub-millisecond failover.

Sovereign-Grade Residency

EU, US, APAC data residency options. Air-gapped on-premise deployment for defense and sovereign clients.

Legal FAQ

Frequently Asked Questions

What are the eight Perception X2 legal surfaces?+
The eight legal surfaces are: Privacy Policy, Terms of Service, Security, Compliance, Acceptable Use, Cookies Policy, Data Processing, and Service Level Agreement. Each addresses a distinct legal or compliance surface that governs engagement with the Perception X2 platform.
Is Perception X2 GDPR compliant?+
Yes. Perception X2 is fully GDPR compliant. We have a Data Processing Addendum (Article 28), support the right to erasure (Article 17), maintain records of processing (Article 30), implement security of processing (Article 32), and use Standard Contractual Clauses for cross-border transfers.
What security certifications does Perception X2 hold?+
Perception X2 holds SOC 2 Type II, ISO/IEC 27001:2022, and is GDPR, CCPA, and HIPAA-eligible. The platform uses AES-256 encryption, TLS 1.3, and zero trust architecture. We have zero security incidents in 15+ years of operation.
How is data residency handled?+
Perception X2 supports EU, US, and APAC data residency with multi-region active-active deployment. Sovereign clients can opt for cryptographic isolation per engagement. Air-gapped on-premise deployment is available for defense and classified environments.
What is the contractual SLA?+
Perception X2's contractual SLA guarantees 99.9999% uptime (31.5s downtime per year), sub-second stream latency, sub-200ms API response at p99, and 24/7 incident response. Remedy credits are issued on SLA breach.
Does Perception X2 support HIPAA?+
Yes. Perception X2 is HIPAA-eligible. For healthcare clients, we sign a Business Associate Agreement (BAA) and implement additional technical safeguards as required by the HIPAA Security Rule.
How does Perception X2 handle data subject access requests?+
Data subject access requests are processed within 30 days, with full data export in machine-readable format. Right to erasure (Article 17 GDPR) is implemented with verified deletion across all systems, including backups within their retention window.
Where can I find the sub-processor list?+
The current sub-processor list is published in the Data Processing page (/legal/data-processing). We provide at least 30 days' notice of sub-processor changes, and clients retain the right to object.
What is the Acceptable Use Policy?+
The Acceptable Use Policy defines permitted and prohibited use of the Perception X2 platform. We do not support use cases that violate international sanctions, target vulnerable populations, promote violence, or facilitate illegal activity. Brand-safety guardrails are configurable per engagement.
How are cookies used on Perception X2 properties?+
Cookies are used for essential platform functionality, analytics, and user preferences. We use categorized, opt-in cookies with granular user controls. No advertising or third-party tracking cookies are set without explicit consent.
Engage with Confidence

Eight surfaces. Defense-grade trust.

Every Perception X2 engagement is governed by clear legal, security, and compliance terms. The eight legal surfaces ensure transparency, auditability, and protection for both client and platform.

8 legal surfaces
SOC 2 Type II
ISO 27001
GDPR compliant
Zero incidents