Trust centre

Standards, controls and data handling

Reference information for security reviews, DPA redlines and regulatory filings. Puccha operates as a data processor for organisations regulated under the Thai PDPA and, where applicable, Bank of Thailand, SEC, OIC and HA requirements.

Last reviewed:

This page summarises our position for review purposes. The Data Processing Agreement is the contractual source of truth; where the two differ, the DPA governs.

1. Certification status

ISO/IEC 27001:2022

Not certified

Not certified. A Statement of Applicability mapped to Annex A and the supporting evidence pack are available now; certification is in progress. We will not represent Puccha as certified until a certificate is issued.

SOC 2 Type II

Not certified

No report issued. Controls are designed against the Trust Services Criteria and an observation window is planned. Ask for current status in writing before relying on it.

PDPA (Thailand)

In operation

In scope and operating. Appointed data protection officer, records of processing, a DPA with a Thai-law overlay, and the data-subject rights surfaces listed below.

Sub-processor certifications

In operation

Cloudflare holds ISO 27001, SOC 2 and PCI DSS; Stripe holds PCI DSS. These are their certifications, not ours, and do not certify Puccha.

2. Who is responsible for what

You, as data controller

  • Establish a lawful basis for the content you upload and the conversations you collect
  • Ensure your privacy notice covers AI processing, visitor uploads and sub-processor disclosure
  • Decide retention periods and who may access what
  • Notify your supervisory authority and data subjects when required

Puccha, as data processor

  • Process only on your instructions and only for the purposes in the DPA
  • Maintain the security measures listed below
  • Disclose sub-processors and give 30 days notice before adding one
  • Notify you of a breach within 24 hours and assist with your filing
  • Return or delete data at the end of the contract

3. Regulatory control mapping

Regulation What it requires What Puccha does
PDPA §28/29 Cross-border transfer safeguards DPA with Thai SCC overlay, Anthropic DPA referenced
PDPA §33 Data-subject access and erasure Export and erasure APIs — tenant-wide and per-visitor
PDPA §37 Controller security duties; deletion once the retention period ends Documented technical and organisational measures; query log stores a hash, not the question; retention configurable per plan
BOT FPG 19/2599 Outsourced-IT risk, ISO 27001-aligned controls ISO 27001-aligned SoA and evidence pack (certification in progress) roadmap
SEC Chapter 2 Data and application security, IAM Per-document ACL, SAML SSO, audit-log export
OIC IT-risk framework 72-hour cyber-incident reporting by the insurer We notify you within 24 hours and assist your filing, so the 72-hour window stays yours to meet; breach automation is in progress roadmap
HA accreditation Documented policy and access control Patient-data-aware ACL guardrails, DPO appointment support
SOC 2 Third-party assurance report Controls built to SOC 2; Type II report on the roadmap roadmap

Rows marked in progress are not offered as implemented controls and must not be relied on in a filing. Ask us for written confirmation of current status first.

4. Sub-processor register

Customers are notified at least 30 days before a new sub-processor is engaged. This register is the current state; the contractual list lives in §6 of the DPA.

Sub-processor Service Data processed Region Transfer safeguard
Cloudflare, Inc. Workers, D1, R2, KV, Vectorize, AI Gateway, Email Sending, Workers AI All categories of processed data Singapore (APAC primary) + global edge Cloudflare DPA + Standard Contractual Clauses (signed)
Anthropic, PBC Claude Haiku 4.5 inference (text and vision) Conversation text, and image bytes on vision turns US-WEST-2 primary; EU available on Enterprise Anthropic Enterprise agreement + Zero Data Retention addendum (signed 2026-05-09) + SCCs. Input is not retained beyond inference, and no abuse-monitoring retention window applies.
Cohere, Inc. Rerank v3.5 (search result ordering) Search query text and retrieved passage text United States Standard Contractual Clauses (signed)
Sentry GmbH Application error monitoring Stack traces and redacted request metadata. Attachment URLs and file bytes are scrubbed before sending. EU and US, per project configuration EU Standard Contractual Clauses + UK addendum
Stripe, Inc. Payment processing Tenant billing details only — no end-user or document data United States and EU Stripe DPA + SCCs

5. Data-subject rights

Right How it is served Response time
Access Export endpoint returning a signed archive, attachments included Within 30 days; usually same session
Rectification Per-attachment delete in the widget; per-message edit for admins Same session
Erasure Cascading delete across object storage, database, the model provider’s file API, and audit-log tombstones Within 30 days
Restriction of processing Processing-paused flag on the individual’s record Immediate
Portability Same export endpoint, JSON manifest plus binaries Within 30 days
Withdrawal of consent Consent revoke flag; forward-only — prior uploads persist until erasure is requested Immediate

6. Security measures

Area Measure
Encryption in transit TLS 1.3 enforced, HSTS, no fallback
Encryption at rest AES-256 across all sub-processors
Access control Role-based access per organisation (owner, admin, editor, viewer) with per-document ACLs; multi-factor authentication for agent accounts
Network Web application firewall rules, request rate limits, session limits
Application Strict Content-Security-Policy, HSTS, content-type pinning, and untrusted retrieved content wrapped in explicit context blocks to resist prompt injection
Logging Immutable, hash-chained audit log; per-event read logging for attachments
Backup and availability Object storage rated eleven nines of durability; daily database export
Data minimisation Query text stored as a hash, filenames hashed, no personal data in audit-log payloads, error reports scrubbed before transmission
Personnel Confidentiality agreements; background checks for staff with production access

7. Breach notification

24h

Puccha notifies you

From becoming aware of a breach affecting your data, per §13 of the DPA.

72h

You notify the regulator

You are the controller and own onward notification to the PDPC or its EU equivalent, and to data subjects where required. We assist with the filing.

8. Retention and end of contract

9. Service level targets

99.95%

Enterprise availability target, rolling 30d

2,000ms

Enterprise chat p95 latency target

24h

Breach notification to you (DPA §13)

Targets are measured over a rolling 30-day window and vary by plan. Current measured values are published on the status page. Status

10. Documents available on request

For a document, a completed security questionnaire, or written confirmation of a control status, contact sales@puccha.co.th.