Skip to main content

Compliance

Hyrax is built and operated by Iru. Hyrax is in scope as an additional product under Iru's SOC 2 Type II program: the audit report is issued by Iru, and Hyrax is the technical scope inside it. Evidence collection accrues from the start of the Type II observation period on 2026-06-22.

Scope at a glance: the SOC 2 system is the Hyrax production environment only; non-production environments are outside the boundary and do not process production customer data.

What you can request

  • SOC 2 status & evidence. Hyrax's Type II observation window opened 2026-06-22 (runs ~12 months, through 2027-06-22); the first Type II report issues after that window closes. In the meantime, we can share interim evidence under NDA: the system boundary (an explicit in-scope / out-of-scope statement), the controls matrix (how Hyrax implements each SOC 2 Trust Services Criterion), the Iru control matrix (how Iru's control set maps to the Hyrax implementation), our open SOC 2 action items and evidence tracking, and the launch-readiness summary of the controls in place before launch. Email security@hyrax.dev or your account team.
  • Article 28 DPA. Iru's data-processing agreement covers Hyrax; the third parties Hyrax relies on are disclosed as sub-processors. Standard contractual clauses (SCCs) are included where applicable.
  • Sub-processor list. See Sub-processors for the authoritative catalog and the data-handling boundary at each one.
  • Data handling & security. See Security for what we store, how it's protected, and how to delete it. The full data-handling, retention, and erasure description is available under NDA.
  • Data retention. Retention windows for your code, findings, backups, and audit records are summarized on the Security page; the full data-handling, retention, and erasure description is available under NDA.

How to report a security or compliance issue

Email security@hyrax.dev. We acknowledge within one business day and aim for an initial assessment within five business days. Please give us reasonable time to remediate before public disclosure.

Standards in scope

StandardStatusNotes
SOC 2 Type IIObservation period began 2026-06-22First report covers the 2026-06-22 → 2027-06-22 observation window. This window is anchored to Hyrax's general-availability date; earlier published material may cite a provisional date in early June 2026, which preceded general availability.
GDPRCompliantYou are the data controller; Iru (Hyrax) acts as your data processor, with the vendors listed in Sub-processors as sub-processors. DPA and lawful-bases statement available on request
CCPA / CPRACompliantDSAR requests honored case-by-case at launch
ISO 27001Not pursuedNo active roadmap
HIPAANot in scopeHyrax does not process PHI