Zdravo's public compliance page describes the controls that are actually implemented today. It does not present planned certifications, future regions, or audit programs as completed facts.
Current security controls
Row-level security and organization-scoped access controls
Authenticated agent identity and governed invocation checks
Policy evaluation before governed execution
Audit and provenance records for governed activity
Authenticated guest-memory claiming and scoped public sharing
Postgres-backed retention, deletion, and data-management controls
What we are not claiming
SOC 2: Zdravo is not represented as SOC 2 certified on this site.
GDPR certification: GDPR is a legal framework, not a certification badge. Zdravo provides data-management controls and can discuss processing requirements with customers.
Custom residency: EU, UK, and on-premise residency options are not presented as live defaults.
SLA: The public site does not promise a 99.9% contractual SLA unless a customer agreement specifically provides one.
Need a security questionnaire, DPA discussion, or architecture review?