Compliance and Certifications (SOC 2, GDPR)
SOC 2-ready: controls aligned to SOC 2, formal Type II audit not yet completed. GDPR-aligned.
Last updated October 3, 2026
Peony's current compliance posture, and what we can share for a security review.
For encryption, hosting, and access control, see Security Overview.
SOC 2
SOC 2 Type II-ready: our controls are aligned to SOC 2, and the Type II audit is underway (via Sprinto).
For a compliance review we can:
- Sign a DPA for GDPR and standard vendor contracts.
- Complete your security questionnaire or vendor-risk form.
- Walk your team through encryption, hosting and access control. The Security Overview covers the basics.
Contact deqian@peony.ink with your company name and review timeline.
GDPR
Peony's practices are aligned with GDPR for EU customers.
- Legal basis. Processing under legitimate-interest and contract bases (GDPR Article 6). Customer content processed only to deliver the service.
- DPA. Standard DPA with Standard Contractual Clauses (SCCs) for international transfers, on request from deqian@peony.ink.
- Data subject rights. Access, portability, correction, and erasure via the account owner or deqian@peony.ink.
- Hosting. Customer data hosted in AWS US by default. EU transfers governed by SCCs. EU-region hosting is available on the Enterprise plan.
EU-residency requirements: EU-region hosting is offered on Enterprise — contact sean@peony.ink before purchasing.
HIPAA
Peony can support HIPAA on a case-by-case basis. Contact sean@peony.ink to discuss your requirements.
CCPA
Peony respects CCPA rights for California residents: right to know, delete, and opt out of sale. Peony does not sell customer data. Submit requests to deqian@peony.ink.
ISO 27001, FedRAMP, Others
ISO 27001-ready — the audit is underway (via Sprinto), alongside our SOC 2 work. FedRAMP, ISO 27017, ISO 27018, and PCI DSS are not currently held; that part of the roadmap is driven by enterprise customer demand — if a certification is blocking procurement, contact sean@peony.ink.
Common Questions
"Can I get a signed DPA?"
Yes — deqian@peony.ink.
"Can you complete our security questionnaire?"
Yes. Send it to deqian@peony.ink.
"Where is our data hosted?"
AWS US region (us-east-1).
"Who on the Peony team has access to our data?"
Peony staff can't open, move or edit the documents in your room. They see account-level information only, such as usernames, NDA signing status and account status.
"What happens to our data if we cancel?"
When you cancel, your plan runs to the end of the paid period. After that, your rooms and files are kept for 30 days by default (longer on request), and resubscribing within that window restores closed rooms in full. If you ask us to delete your account and data, it's removed permanently and can't be restored afterwards. See Delete your account and data.
"Does Peony use our documents to train AI models?"
No. LLM APIs operate under data-handling agreements that prohibit training on customer content.
