Trust centre
Standards, controls and data handling
Reference information for security reviews, DPA redlines and regulatory filings. Puccha operates as a data processor for organisations regulated under the Thai PDPA and, where applicable, Bank of Thailand, SEC, OIC and HA requirements.
Last reviewed:
This page summarises our position for review purposes. The Data Processing Agreement is the contractual source of truth; where the two differ, the DPA governs.
1. Certification status
ISO/IEC 27001:2022
Not certifiedNot certified. A Statement of Applicability mapped to Annex A and the supporting evidence pack are available now; certification is in progress. We will not represent Puccha as certified until a certificate is issued.
SOC 2 Type II
Not certifiedNo report issued. Controls are designed against the Trust Services Criteria and an observation window is planned. Ask for current status in writing before relying on it.
PDPA (Thailand)
In operationIn scope and operating. Appointed data protection officer, records of processing, a DPA with a Thai-law overlay, and the data-subject rights surfaces listed below.
Sub-processor certifications
In operationCloudflare holds ISO 27001, SOC 2 and PCI DSS; Stripe holds PCI DSS. These are their certifications, not ours, and do not certify Puccha.
2. Who is responsible for what
You, as data controller
- Establish a lawful basis for the content you upload and the conversations you collect
- Ensure your privacy notice covers AI processing, visitor uploads and sub-processor disclosure
- Decide retention periods and who may access what
- Notify your supervisory authority and data subjects when required
Puccha, as data processor
- Process only on your instructions and only for the purposes in the DPA
- Maintain the security measures listed below
- Disclose sub-processors and give 30 days notice before adding one
- Notify you of a breach within 24 hours and assist with your filing
- Return or delete data at the end of the contract
3. Regulatory control mapping
| Regulation | What it requires | What Puccha does |
|---|---|---|
| PDPA §28/29 | Cross-border transfer safeguards | DPA with Thai SCC overlay, Anthropic DPA referenced |
| PDPA §33 | Data-subject access and erasure | Export and erasure APIs — tenant-wide and per-visitor |
| PDPA §37 | Controller security duties; deletion once the retention period ends | Documented technical and organisational measures; query log stores a hash, not the question; retention configurable per plan |
| BOT FPG 19/2599 | Outsourced-IT risk, ISO 27001-aligned controls | ISO 27001-aligned SoA and evidence pack (certification in progress) roadmap |
| SEC Chapter 2 | Data and application security, IAM | Per-document ACL, SAML SSO, audit-log export |
| OIC IT-risk framework | 72-hour cyber-incident reporting by the insurer | We notify you within 24 hours and assist your filing, so the 72-hour window stays yours to meet; breach automation is in progress roadmap |
| HA accreditation | Documented policy and access control | Patient-data-aware ACL guardrails, DPO appointment support |
| SOC 2 | Third-party assurance report | Controls built to SOC 2; Type II report on the roadmap roadmap |
Rows marked in progress are not offered as implemented controls and must not be relied on in a filing. Ask us for written confirmation of current status first.
4. Sub-processor register
Customers are notified at least 30 days before a new sub-processor is engaged. This register is the current state; the contractual list lives in §6 of the DPA.
| Sub-processor | Service | Data processed | Region | Transfer safeguard |
|---|---|---|---|---|
| Cloudflare, Inc. | Workers, D1, R2, KV, Vectorize, AI Gateway, Email Sending, Workers AI | All categories of processed data | Singapore (APAC primary) + global edge | Cloudflare DPA + Standard Contractual Clauses (signed) |
| Anthropic, PBC | Claude Haiku 4.5 inference (text and vision) | Conversation text, and image bytes on vision turns | US-WEST-2 primary; EU available on Enterprise | Anthropic Enterprise agreement + Zero Data Retention addendum (signed 2026-05-09) + SCCs. Input is not retained beyond inference, and no abuse-monitoring retention window applies. |
| Cohere, Inc. | Rerank v3.5 (search result ordering) | Search query text and retrieved passage text | United States | Standard Contractual Clauses (signed) |
| Sentry GmbH | Application error monitoring | Stack traces and redacted request metadata. Attachment URLs and file bytes are scrubbed before sending. | EU and US, per project configuration | EU Standard Contractual Clauses + UK addendum |
| Stripe, Inc. | Payment processing | Tenant billing details only — no end-user or document data | United States and EU | Stripe DPA + SCCs |
5. Data-subject rights
| Right | How it is served | Response time |
|---|---|---|
| Access | Export endpoint returning a signed archive, attachments included | Within 30 days; usually same session |
| Rectification | Per-attachment delete in the widget; per-message edit for admins | Same session |
| Erasure | Cascading delete across object storage, database, the model provider’s file API, and audit-log tombstones | Within 30 days |
| Restriction of processing | Processing-paused flag on the individual’s record | Immediate |
| Portability | Same export endpoint, JSON manifest plus binaries | Within 30 days |
| Withdrawal of consent | Consent revoke flag; forward-only — prior uploads persist until erasure is requested | Immediate |
6. Security measures
| Area | Measure |
|---|---|
| Encryption in transit | TLS 1.3 enforced, HSTS, no fallback |
| Encryption at rest | AES-256 across all sub-processors |
| Access control | Role-based access per organisation (owner, admin, editor, viewer) with per-document ACLs; multi-factor authentication for agent accounts |
| Network | Web application firewall rules, request rate limits, session limits |
| Application | Strict Content-Security-Policy, HSTS, content-type pinning, and untrusted retrieved content wrapped in explicit context blocks to resist prompt injection |
| Logging | Immutable, hash-chained audit log; per-event read logging for attachments |
| Backup and availability | Object storage rated eleven nines of durability; daily database export |
| Data minimisation | Query text stored as a hash, filenames hashed, no personal data in audit-log payloads, error reports scrubbed before transmission |
| Personnel | Confidentiality agreements; background checks for staff with production access |
- Every database query scoped by tenant — cross-tenant tests gate every endpoint in CI.
- Per-document ACLs with ReBAC and ABAC; retrieval filters before generation, not after.
- Hash-chained audit log; admin access to a conversation is logged and visible to the data subject.
- Query text stored hashed — no raw questions at rest.
- API keys stored as SHA-256 hashes. Injection patterns rejected; the system prompt is never echoed.
- Runs on Cloudflare’s edge — Bangkok latency, isolated data stores per environment.
7. Breach notification
Puccha notifies you
From becoming aware of a breach affecting your data, per §13 of the DPA.
You notify the regulator
You are the controller and own onward notification to the PDPC or its EU equivalent, and to data subjects where required. We assist with the filing.
8. Retention and end of contract
- Conversation retention is configurable per plan; the query log stores a hash of the question, never the question text.
- On termination, live data is retained for 30 days so the account can be reactivated without loss.
- After 30 days the data is hard-deleted from the database, object storage and gateway logs.
- Audit-log tombstones survive deletion. They record that data existed and was deleted — not what it contained.
9. Service level targets
99.95%
Enterprise availability target, rolling 30d
2,000ms
Enterprise chat p95 latency target
24h
Breach notification to you (DPA §13)
Targets are measured over a rolling 30-day window and vary by plan. Current measured values are published on the status page. Status
10. Documents available on request
For a document, a completed security questionnaire, or written confirmation of a control status, contact sales@puccha.co.th.