> ## Documentation Index
> Fetch the complete documentation index at: https://vlyai-1c28d863.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Compliance

> GDPR, SOC 2, HIPAA, ISO 27001 — current status and how vly customers use vly's controls to meet their own obligations.

## Current status

| Standard | Status |
| - | - |
| **GDPR** | Compliant. DPA available; data export and deletion supported. |
| **SOC 2 Type II** | Audit in progress. Report available to Enterprise customers on request. |
| **HIPAA** | Not currently supported. Roadmap. |
| **ISO 27001** | Roadmap. |

## DPA (Data Processing Agreement)

vly offers a standard DPA on request to customers processing personal data of EU / UK residents. Email [legal@vly.ai](mailto:legal@vly.ai).

## Sub-processors

vly uses the following sub-processors:

| Vendor | Purpose | Region |
| - | - | - |
| Convex | Database, function runtime | US |
| Anthropic | Claude Code agent | US |
| OpenAI | Codex agent | US |
| Google | Gemini agent | US |
| AWS | Hosting, CDN | Multi-region |
| Stripe | Billing | US/EU |

Subscribe to sub-processor changes at [vly.ai/sub-processors](https://vly.ai/sub-processors).

## Data residency

By default, customer data lives in the US. EU residency available for Enterprise customers on request.

## Data retention

| Data | Retention |
| - | - |
| Active project data | Indefinite (you control) |
| Deleted project data | 30 days, then purged |
| Workspace audit log | Per plan (7 days to 1 year) |
| Backups | 7 days (Free) / 30 days (Pro) / 90 days (Business) / 1 year (Enterprise) |

## What customers do for their own compliance

* **GDPR**: vly provides the controls; you're responsible for using them. See [Data export](/security/data-export) and [Account deletion](/security/account-deletion).
* **SOC 2 / HIPAA**: customers building healthcare or finance apps on vly need their own audit; vly's controls support but don't substitute.

## Reporting a security issue

[security@vly.ai](mailto:security@vly.ai). See the disclosure policy in [Security overview](/security/overview).

## Related

<CardGroup cols={3}>
  <Card title="Security overview" icon="shield" href="/security/overview">
    Broader model.
  </Card>

  <Card title="Data export" icon="download" href="/security/data-export">
    GDPR-grade export.
  </Card>

  <Card title="Account deletion" icon="user-minus" href="/security/account-deletion">
    GDPR-grade deletion.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.