Reference Library
Compliance Frameworks
What each of these actually requires, structurally — not legal advice, and not a claim that we hold any of these certifications ourselves. Formal certification is always issued by an accredited third-party auditor, never a software vendor.
GDPR (General Data Protection Regulation)
The EU's data protection law — applies to any organization processing personal data of people in the EU, regardless of where the organization itself is based.
CCPA/CPRA (California Consumer Privacy Act / Privacy Rights Act)
California's consumer privacy law — grants California residents rights over their personal data and applies to businesses meeting certain revenue or data-volume thresholds.
HIPAA (Health Insurance Portability and Accountability Act)
The US federal law governing how healthcare providers, insurers, and their vendors handle Protected Health Information (PHI).
PCI-DSS (Payment Card Industry Data Security Standard)
The security standard for any organization that stores, processes, or transmits payment card data.
SOC 2 Type II
An audit framework (not a government regulation) that's become the default trust signal enterprise B2B customers require from software vendors.
ISO 27001
The international standard for an Information Security Management System (ISMS) — a systematic, risk-based approach to managing security, not a one-time checklist.
DPDP Act (India's Digital Personal Data Protection Act)
India's comprehensive data protection law — directly relevant given Vajra is based in India, and increasingly relevant to any business processing Indian residents' data.