Compliance Center
Compliance & Trust Center
PsyData Labs L.L.C. (PDL) operates with a deep commitment to enterprise security, privacy, and responsible AI governance. Our integrated compliance program establishes defense-in-depth controls across people, processes, and technology, designed to safeguard our clients' most sensitive behavioral and psychological data. Our framework maps comprehensively to leading global standards and regulatory regimes, including SOC 2 Type II, ISO/IEC 27001 (Information Security Management) and ISO/IEC 27701 (Privacy Information Management), the NIST Cybersecurity Framework (CSF), the NIST AI Risk Management Framework (AI RMF), the New York SHIELD Act (NY GBL §899-aa), the California Privacy Rights Act (CPRA), and the EU General Data Protection Regulation (GDPR).
1. Information Security & Infrastructure Controls
PDL’s security posture is continuously monitored and externally validated to ensure the protection of our infrastructure and data assets. Our security measures adhere to SOC 2 criteria for Security, Availability, and Confidentiality, alongside NIST CSF principles (Identify, Protect, Detect, Respond, Recover).
- Advanced Encryption: All data in transit is protected using TLS 1.2+ (with a baseline transition to TLS 1.3), while data at rest is secured via AES-256 encryption. We utilize strict Key Management Services (KMS) with automated key rotation for all S2 (Sensitive) to S4 (Highly Restricted) data classifications.
- Identity & Access Management (IAM): We enforce Zero Trust principles, the Principle of Least Privilege (PoLP), and mandatory phishing-resistant Multi-Factor Authentication (MFA) across all employee and administrative access. Privileged access requires temporary, just-in-time (JIT) provisioning.
- Vulnerability & Threat Management: Continuous dynamic and static application security testing (DAST/SAST) is integrated into our Secure Development Lifecycle (SDLC). We maintain strict Service Level Agreements (SLAs) for vulnerability remediation and conduct comprehensive third-party penetration testing annually.
- Resilience & Observability: Cloud infrastructure is configured via Infrastructure-as-Code (IaC) to guarantee immutability. Centralized Security Information and Event Management (SIEM) provides real-time logging, anomaly detection, and automated alerting.
2. Privacy, Data Governance & Subject Rights
We champion "Privacy by Design" in every product iteration. PDL respects the rights of individuals and executes processing activities in strict adherence to CPRA, GDPR, and the NY SHIELD Act.
- Data Classification Taxonomy: Our data architecture is strictly segmented by a tiering system (S0 to S4) and domain-specific markers (D-BEH for Behavioral, D-PSY for Psychological, and D-INF for Inferred insights) to ensure access is contextually bounded and legally permissible.
- Data Subject Access Rights (DSAR): Our dedicated privacy operations team processes requests for data access, rectification, deletion, and portability within statutory limits—guaranteeing compliance with the 45-day window under CPRA and the 30-day window under GDPR.
- Data Minimization & Retention: We strictly limit the collection of Personal Identifiable Information (PII) to stated business purposes. Automated retention and cryptographic deletion policies ensure data is permanently destroyed when no longer necessary.
- Cross-Border Data Transfers: International data transfers are governed by executed Standard Contractual Clauses (SCCs) and Transfer Impact Assessments (TIAs) to guarantee lawful transfer mechanisms for global clientele.
3. Responsible AI & Algorithmic Governance
As a leader in processing behavioral and psychological signals, PDL recognizes the profound impact of AI. Our AI governance strategy aligns with the NIST AI RMF and anticipated requirements of the EU AI Act.
- Risk Tiering & Impact Assessments: All models undergo rigorous AI Risk Assessments. High-impact analytical models require a mandatory Human-in-the-Loop (HITL) review cycle before operational deployment.
- Bias Mitigation & Algorithmic Fairness: Models are continuously tested for bias, drift, and fairness across demographic slices. Output anomalies are flagged and addressed before production rollout.
- Explainability & Transparency: We enforce model explainability metadata on all S3+ output inferences, ensuring that AI-driven psychological profiling can be audited, understood, and contextualized.
- Safe Data Environments: Sensitive D-PSY and D-BEH data are barred from non-production environments unless anonymized through state-of-the-art synthetic data generation or differential privacy techniques, eliminating memorization leakage risks.
4. Vendor Risk Management & Subprocessors
Security extends throughout our entire supply chain. All prospective vendors and subprocessors are subjected to rigorous Third-Party Risk Management (TPRM) assessments before integration.
- Vendor Assessments: We evaluate the security, privacy, and compliance posture of all third parties, ensuring their alignment with our ISO 27001 and SOC 2 requirements.
- Contractual Binding: All data sharing is governed by stringent Data Processing Agreements (DPAs), including Article 28-style clauses, ensuring our partners uphold data deletion requirements and subprocessor notification standards.
5. Incident Response & Breach Communication
PDL maintains a tested Incident Response Policy and Playbook designed to contain threats swiftly and transparently.
- Regulatory Reporting: We are committed to notifying supervisory authorities (e.g., within 72 hours under GDPR) and affected individuals in accordance with the NY SHIELD Act, CPRA, and other applicable breach notification laws.
- Client Notification: Enterprise clients and partners receive expedited contractual notifications as defined by mutually executed DPAs and Service Level Agreements (SLAs).
6. Contact Information & Legal Requests
We believe that trust is built on transparency and accessibility. For compliance inquiries, audits, or data requests, please contact our teams:
- Data Privacy & DSARs: privacy@psydatalabs.com
- Security Operations: security@psydatalabs.com
- Compliance & Ethics: compliance@psydatalabs.com
- Legal Affairs: legal@psydatalabs.com