> ## Documentation Index
> Fetch the complete documentation index at: https://docs.graphorlm.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Compliance

> Graphor's honest certification status, the inherited certifications from subprocessors that cover the upstream chain, and the inventory of compensating controls in place where a formal certification does not yet exist.

## The stance

This page is intentionally honest about what is and is not certified. Graphor is operated by Synapse Inovação e Tecnologia LTDA., a company at an early-stage. It does not yet hold its own SOC 2 Type II or ISO 27001 certification. Stating that openly is the first compensating control.

What this page commits to:

* **No aspirational certification dates.** Where a certification is under evaluation, the page says so without binding to a delivery date. When a date is committed, this page is updated and the change history at the bottom records it.
* **Every control claim in the rest of the Trust Center is verifiable.** Each row in the [compensating-controls inventory](#3-compensating-controls-inventory) below links to the Trust Center page that documents the control in implementation detail.
* **Inherited certifications are listed verbatim with links.** Where Graphor relies on a subprocessor's certified posture, the certification is named with its issuing standard and the customer can read the same report under NDA.

For enterprise customers that contractually require Graphor itself to hold a specific certification, see [§6](#6-how-to-request-audit-reports-and-discuss-certification-needs) at the bottom of this page for the path forward.

## 1. Synapse's own certification status

| Certification                                      | Current status                     | Committed timeline | Compensating controls (see [§3](#3-compensating-controls-inventory))                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| -------------------------------------------------- | ---------------------------------- | ------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **SOC 2 Type II**                                  | Evaluating; no committed date      | None today         | Full set in [§3](#3-compensating-controls-inventory)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| **ISO/IEC 27001**                                  | Evaluating; no committed date      | None today         | Full set in [§3](#3-compensating-controls-inventory)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| **ISO/IEC 27017** (cloud services security)        | Evaluating; no committed date      | None today         | Inherited from the cloud infrastructure provider — see [§2](#2-inherited-certifications)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| **ISO/IEC 27018** (PII in public cloud)            | Evaluating; no committed date      | None today         | Inherited from the cloud infrastructure provider — see [§2](#2-inherited-certifications)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| **ISO/IEC 27701** (privacy information management) | Not evaluated                      | None today         | Compensated by LGPD / GDPR alignment per [§4](#4-regime-based-posture)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| **PCI DSS**                                        | Not applicable to Synapse directly | n/a                | Payment-card data is processed by Stripe — see [Subprocessors §5](/trust/subprocessors#5-payment-and-billing); Graphor stores only payment metadata                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| **HIPAA**                                          | Not in scope today                 | n/a                | Graphor is not currently positioned as a HIPAA-Business-Associate. **Gap to BAA-eligibility** for a healthcare customer would require coverage across the Security Rule (45 CFR §§ 164.302–318), Privacy Rule (§§ 164.500–534), and Breach Notification Rule (§§ 164.400–414). Specifically: (i) Google Cloud BAA (available — Synapse would execute), (ii) AWS BAA covering Bedrock (available — Synapse would execute), (iii) Stripe BAA (n/a — billing-only, no PHI transit), (iv) **administrative safeguards** (45 CFR § 164.308) — training, sanctions, workforce policies (largely present per [Tenant Isolation §7](/trust/tenant-isolation#7-personnel-security) but require HIPAA-specific scoping), (v) **technical safeguards** including audit controls (45 CFR § 164.312(b)) and person/entity authentication (§ 164.312(d)) — current MFA posture supports (d); the customer-facing audit-log API needed for (b) is on the roadmap, (vi) **organizational requirements** (45 CFR § 164.314) — BAA-required content and subprocessor BAAs, (vii) **PHI-Project posture commitment** — observability tracing remains off by default for the Project (current Enterprise default); the gap is contractually binding this for any PHI Project, (viii) breach-notification mapping to 45 CFR § 164.404 alongside the existing LGPD/GDPR notification. Not on roadmap today; revisit on first healthcare enterprise engagement via [privacy@graphorlm.com](mailto:privacy@graphorlm.com). |
| **FedRAMP**                                        | Not in scope today                 | n/a                | Out of scope — Graphor is not positioned for US-federal-government workloads                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |

The "evaluating" status on SOC 2 Type II and ISO 27001 reflects an active assessment of when it makes sense to enter the audit cycle. Enterprise contracts that require either certification can accelerate the timeline — see [§6](#6-how-to-request-audit-reports-and-discuss-certification-needs).

## 2. Inherited certifications

Graphor's operational stack runs on subprocessors that carry the certifications listed below. Inheritance is not a substitute for Graphor holding its own certification, but it is the standard way that a SOC 2-pending company demonstrates that the upstream chain meets enterprise security expectations.

| Subprocessor                                                                   | Certifications and audit reports                                                                                                                                                                                          |
| ------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Google Cloud Platform** (production cloud infrastructure including identity) | ISO/IEC 27001, 27017, 27018, 27701; SOC 1, SOC 2 Type 2, SOC 3; PCI DSS Level 1; FedRAMP High; HIPAA BAA available. Reports: [Google Cloud compliance offerings](https://cloud.google.com/security/compliance/offerings). |
| **Amazon Web Services** (Bedrock)                                              | ISO/IEC 27001, 27017, 27018, 27701; SOC 1, SOC 2, SOC 3; PCI DSS Level 1; FedRAMP. Reports: [AWS compliance programs](https://aws.amazon.com/compliance/programs/).                                                       |
| **OpenAI** (embeddings)                                                        | SOC 2 Type 2. Reports: [OpenAI Trust Portal](https://trust.openai.com/).                                                                                                                                                  |
| **Cerebras** (chunk enrichment + fast tier)                                    | SOC 2 Type 2. Reports: available on request from Cerebras under NDA.                                                                                                                                                      |
| **Stripe** (payment processing)                                                | PCI DSS Level 1; SOC 1, SOC 2 Type 2; ISO/IEC 27001. Reports: [Stripe Privacy and Compliance](https://stripe.com/privacy).                                                                                                |
| **Neo4j AuraDB** (managed graph store)                                         | SOC 2 Type 2; ISO/IEC 27001. Reports: [Neo4j Trust Center](https://neo4j.com/trust-center/).                                                                                                                              |

Each subprocessor's audit reports can be requested through Synapse via [privacy@graphorlm.com](mailto:privacy@graphorlm.com); the report itself is delivered by the subprocessor under their own NDA terms.

## 3. Compensating controls inventory

In the absence of Synapse's own SOC 2 or ISO 27001 certification, the following operational controls — already in place and documented elsewhere on the Trust Center — cover the gap that the certification would otherwise demonstrate.

| Control area (SOC 2 / ISO 27001 mapping)  | What Graphor does                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | Where it is documented                                                                                                    |
| ----------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------- |
| Asset inventory and architecture          | Public, sanitized architecture published; every component and data flow documented; production region pinned and verifiable per component.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | [Architecture](/trust/architecture), [Data Residency](/trust/data-residency)                                              |
| Vendor and subprocessor management        | Versioned subprocessor list; 30-day prior-notice commitment for material additions; inherited-certification inventory; related-party disclosure for Synapse Consultoria.                                                                                                                                                                                                                                                                                                                                                                                                                                                         | [Subprocessors](/trust/subprocessors)                                                                                     |
| Encryption at rest and in transit         | Cloud-provider-managed AES-256 default; customer-managed encryption keys available on enterprise request (typical scoping engagement: 4–8 weeks; may carry an incremental fee); TLS 1.2+ enforced on every public surface.                                                                                                                                                                                                                                                                                                                                                                                                       | [Trust Center Overview §3](/trust/overview#3-encryption-posture)                                                          |
| Identity and access management            | Per-project API tokens with TTL + last-used auditing; tier-aware observability access; Project-scoped Synapse-personnel access via role assignment on the observability store today; per-personnel access-audit logging on the observability instance is on the roadmap (see [Tenant Isolation §1](/trust/tenant-isolation#1-isolation-by-layer)).                                                                                                                                                                                                                                                                               | [Tenant Isolation](/trust/tenant-isolation)                                                                               |
| Logical tenant isolation                  | Single-tenant logical model with application-layer scoping at the API, database, graph store, storage, and observability layers; per-layer failure-mode analysis published.                                                                                                                                                                                                                                                                                                                                                                                                                                                      | [Tenant Isolation §1](/trust/tenant-isolation#1-isolation-by-layer)                                                       |
| Data retention and disposal               | Infinite-until-DELETE posture; end-to-end delete cascade; customer-callable DSR API; bounded TTL on observability traces; 7-day database backup + point-in-time recovery window for the primary database. **Billing records are retained for the statutory tax-record window (5 years under CTN art. 173) even after account deletion** — see [Data Retention §6](/trust/data-retention#6-billing-data).                                                                                                                                                                                                                         | [Data Retention](/trust/data-retention)                                                                                   |
| AI / model governance                     | Contractual no-training commitment from every active provider, with verbatim citations; tier-based provider declaration; explicit non-commitments around training-program opt-in, fine-tuning, and human review of customer content.                                                                                                                                                                                                                                                                                                                                                                                             | [Model Use and Training](/trust/model-use-and-training)                                                                   |
| Incident response and breach notification | 72-hour customer notification SLA after internal confirmation; 14-day post-mortem commitment; customer-side reporting path with safe-harbor.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | [Incident Response](/trust/incident-response)                                                                             |
| Privacy program and DSR                   | Privacy policy published in English and Portuguese; DSR API satisfies LGPD art. 18 and GDPR art. 17; privacy contact channel monitored.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | [Privacy Policy](/legal/privacy-policy), [Data Retention §3](/trust/data-retention#3-the-dsr-api)                         |
| Contractual instruments                   | DPA template available for customer counter-signature; SCC-equivalent international transfer clauses; pass-through clauses referencing upstream DPAs.                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | [DPA Template](/legal/dpa-template)                                                                                       |
| Audit logging                             | Today: API-token last-used metadata, payment-processor billing events, usage metering aggregates, and DSR delete confirmations are customer-visible. The full customer-visible activity log API + UI + export are on the roadmap. Ad-hoc audit queries served via privacy@ within 10 business days for routine queries.                                                                                                                                                                                                                                                                                                          | [Audit Logs](/trust/audit-logs)                                                                                           |
| Vulnerability management                  | Container images built on official base images; dependency scanning in CI; security advisories monitored for every active subprocessor; at least annual review of patch posture. **No third-party penetration test has been performed yet**; compensating controls are the CI dependency scanning, the daily operational-log review in [Incident Response §2](/trust/incident-response#2-detection), and the [vulnerability disclosure program](/trust/incident-response#9-security-research-and-vulnerability-disclosure). A baseline external pentest is planned; the resulting executive summary will be available under NDA. | [Incident Response §9](/trust/incident-response#9-security-research-and-vulnerability-disclosure)                         |
| Disaster recovery                         | Cloud-provider automated backups + point-in-time recovery window; documented restore procedure that preserves customer DSR actions across recoveries.                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | [Data Retention §5](/trust/data-retention#5-backups-and-disaster-recovery), [Incident Response](/trust/incident-response) |
| Business continuity                       | Single-region deployment is intentional; provider redundancy for AI inference (Cerebras + Bedrock both available); founder-incapacitation continuity plan with documented backup-access procedure and named alternate operations contact disclosed to enterprise customers under NDA. Full BCP detail in [§5](#5-business-continuity-and-key-person-risk).                                                                                                                                                                                                                                                                       | This page [§5](#5-business-continuity-and-key-person-risk)                                                                |

Enterprise customers performing a Graphor-specific security questionnaire can use this table as a cross-reference: for each line item on the questionnaire, identify the relevant control area and follow the link to the implementation detail.

## 4. Regime-based posture (LGPD, GDPR)

LGPD and GDPR are regulatory regimes, not certification schemes — there is no formal "LGPD-certified" stamp. Graphor's posture against each is documented as compliance by design, with the relevant articles cited next to the control that satisfies them:

| Regime                                                                                                                                                              | Article / topic                                                                                                                                                                                                      | Where Graphor's posture is documented                                                                                          |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------ |
| LGPD art. 7º (legal bases)                                                                                                                                          | Contractual necessity, consent, legal obligation, legitimate interests                                                                                                                                               | [Privacy Policy](/legal/privacy-policy)                                                                                        |
| LGPD art. 9º (transparency)                                                                                                                                         | Privacy Policy, Trust Center, ToS                                                                                                                                                                                    | This site                                                                                                                      |
| LGPD art. 18 (data-subject rights)                                                                                                                                  | DSR API + privacy contact                                                                                                                                                                                            | [Data Retention §3](/trust/data-retention#3-the-dsr-api)                                                                       |
| LGPD art. 33, II, b (international transfer via standard contractual clauses)                                                                                       | EU SCCs 2021/914 for EU customers, ANPD Cláusulas-Padrão Contratuais (Resolução CD/ANPD nº 19/2024) for Brazilian customers in every subprocessor DPA; single-region production; ZDR on OpenAI                       | [Data Residency §3](/trust/data-residency#3-international-transfer-regime)                                                     |
| LGPD art. 38 (DPIA)                                                                                                                                                 | DPIA template for high-risk processing on request                                                                                                                                                                    | Available on request via [privacy@graphorlm.com](mailto:privacy@graphorlm.com)                                                 |
| LGPD art. 39 (operator's duty to follow controller's instructions); subprocessor authorization is governed contractually under arts. 39 and 42 (solidary liability) | Versioned subprocessor list with notification subscription; documented instructions captured in the Agreement, Trust Center, and DPA per [DPA §3.1](/legal/dpa-template)                                             | [Subprocessors](/trust/subprocessors)                                                                                          |
| LGPD art. 48 (incident notification)                                                                                                                                | 72-hour contractual SLA meets or exceeds the **3-business-day** regulatory floor in ANPD Resolução CD/ANPD nº 15/2024, art. 6                                                                                        | [Incident Response](/trust/incident-response)                                                                                  |
| GDPR art. 5 (data protection principles)                                                                                                                            | Mirrored by the same controls that satisfy LGPD art. 7º and 9º                                                                                                                                                       | This site                                                                                                                      |
| GDPR art. 6 / 9 (lawful basis / special categories)                                                                                                                 | Same legal-basis statement as LGPD art. 7º; no processing of special-category data on a Graphor-product basis (customer may upload it as part of Customer Content under their own legal basis)                       | [Privacy Policy](/legal/privacy-policy)                                                                                        |
| GDPR art. 15–22 (data-subject rights)                                                                                                                               | Same DSR API as LGPD art. 18                                                                                                                                                                                         | [Data Retention §3](/trust/data-retention#3-the-dsr-api)                                                                       |
| GDPR art. 28 (processor obligations)                                                                                                                                | Codified in the DPA template                                                                                                                                                                                         | [DPA Template](/legal/dpa-template)                                                                                            |
| GDPR art. 32 (security of processing)                                                                                                                               | Inherited from Google ISO 27001/27017/27018 + AWS Bedrock equivalents + the compensating controls in [§3](#3-compensating-controls-inventory)                                                                        | This page                                                                                                                      |
| GDPR art. 33(2) (processor-to-controller breach notification)                                                                                                       | 72-hour contractual SLA exceeds the statutory "without undue delay" floor of art. 33(2); the art. 33(1) 72-hour clock binds the controller, not the processor                                                        | [Incident Response](/trust/incident-response)                                                                                  |
| GDPR art. 44–49 (international transfer)                                                                                                                            | Same SCC-equivalent posture as LGPD art. 33                                                                                                                                                                          | [Data Residency §3](/trust/data-residency#3-international-transfer-regime)                                                     |
| EOAB art. 7 (advocacy confidentiality, Brazil)                                                                                                                      | Reinforced by the no-training commitment, the Enterprise-tier observability default-off posture (the recommended default for legal-sector customers), and the DSR API that satisfies the sigilo profissional surface | [Model Use and Training](/trust/model-use-and-training), [Tenant Isolation §4](/trust/tenant-isolation#4-observability-traces) |

## 5. Business continuity and key-person risk

Synapse is operated by SYNAPSE INOVAÇÃO E TECNOLOGIA LTDA., currently founder-led. A founder-led operation carries an explicit key-person risk that customers should evaluate at signature. This section discloses what mitigates that risk today and what does not.

### 5.1 What is in place

* **Provider redundancy for inference.** AWS Bedrock and Cerebras are both active subprocessors; if one provider's availability degrades, traffic is routed to the other within the per-tier provider chain documented in [Model Use and Training §1.2](/trust/model-use-and-training#12-query-time-per-sourcesask-or-data-extraction-request).
* **Data durability.** Cloud-provider automated backups + point-in-time recovery within a 7-day window for the primary database; object-storage redundancy at the cloud-provider tier; managed-graph-store provider redundancy per [Subprocessors §2](/trust/subprocessors#2-cloud-infrastructure-production). See [Data Retention §5](/trust/data-retention#5-backups-and-disaster-recovery).
* **External incident-alerting service.** Inbound mail to the privacy mailbox triggers an external alert that routes to the on-call engineer, providing notification continuity independent of any single device.
* **Backup-access procedure (operationalizing).** Synapse is operationalizing a credential-recovery arrangement for the event of founder incapacitation. The current interim measure is a sealed-credential procedure with a named alternate operations contact (a Brazilian licensed attorney) who can revoke credentials, freeze the production environment, and trigger customer notification under the [Incident Response](/trust/incident-response) SLA. A formal third-party escrow arrangement (cartório or commercial escrow provider) is on the roadmap; the current arrangement and the named alternate contact are disclosed to enterprise customers under NDA.
* **Stateless customer integration.** Customers integrate via the public REST + streaming API; there is no Synapse-deployed customer-side agent that would fail if Synapse-side operations paused.

### 5.2 What is NOT in place (honest disclosure)

* **No 24/7 in-house SecOps rotation.** Severity-1 and Severity-2 alerts route to the founder + external alerting service today. Synapse is investing in a 24/7 escalation path as the team scales; the current model is disclosed rather than overstated.
* **No active-active multi-region deployment.** Per [Data Residency §5](/trust/data-residency#5-why-us-central1), the single-region posture is intentional; the Brazil and EU region roadmap items in [Data Residency §6](/trust/data-residency#6-roadmap) provide a customer-driven path to regional alternatives, not active-active redundancy.
* **No published RTO/RPO commitments today, and no end-to-end restore drill has been run.** The point-in-time recovery within the 7-day backup window targets sub-hour RPO under normal operation (per the cloud-provider PITR granularity, typically seconds-to-minutes); an effective RTO for a full-region rebuild is on the order of hours and depends on the cloud-provider control plane. Quantified RTO/RPO targets will be published once an annual restore-drill cadence is established.
* **No formal vendor-termination wind-down playbook today.** A customer-data export path is available on request via [privacy@graphorlm.com](mailto:privacy@graphorlm.com); a published wind-down playbook is on the roadmap.
* **No published company-dissolution playbook today.** In the event of voluntary or involuntary dissolution of Synapse Inovação e Tecnologia LTDA., Customer Content would be subject to standard Brazilian corporate-dissolution procedures under the Código Civil arts. 1.033–1.038 (sociedade limitada) and the LGPD obligations that survive dissolution. **A formal commitment to (a) provide a 30-day customer-data export window on dissolution notification, (b) certify destruction of remaining Customer Content within 60 days of dissolution, and (c) name a Brazilian licensed attorney as the post-dissolution data-protection contact is available as a contractual rider on enterprise engagements on request.** A published dissolution playbook is on the roadmap.

### 5.3 What customers should do

Customers with stringent business-continuity requirements (regulated financial-sector workloads, healthcare BAA-equivalent, government engagements) should:

* Discuss BCP scope at contract signature, including target RTO/RPO and a vendor-termination wind-down clause specific to the engagement;
* Maintain an independent export of Customer Content at a cadence appropriate to the workload (Graphor provides export on request, and a self-service export API is on the roadmap);
* Subscribe to [subprocessors@graphorlm.com](mailto:subprocessors@graphorlm.com) to receive material-change notifications that may affect continuity posture.

## 6. How to request audit reports and discuss certification needs

For enterprise customers:

* **Subprocessor audit reports** (Google SOC 2, AWS SOC 2, OpenAI SOC 2 Type 2, etc.): request via [privacy@graphorlm.com](mailto:privacy@graphorlm.com). Reports are delivered by the subprocessor under their own NDA terms.
* **A formal Synapse certification commitment** (specific SOC 2 timeline, ISO 27001 scope agreement, HIPAA BAA): request via [privacy@graphorlm.com](mailto:privacy@graphorlm.com). An enterprise contract with a binding certification clause is the path to bringing a specific audit cycle forward.
* **A DPIA / Legitimate Interest Assessment** specific to your processing activity: Synapse can provide a Graphor-side template that you complete with your processing details, on request via [privacy@graphorlm.com](mailto:privacy@graphorlm.com).
* **A custom security questionnaire**: Synapse will complete reasonable enterprise security questionnaires within 10 business days of receipt, citing the Trust Center pages above for the answers wherever they apply.

## Executive intent statement

> Synapse Inovação e Tecnologia LTDA. — the operator of Graphor — is committed to building the controls, the operational discipline, and the audit posture that regulated enterprise customers require. We are honest about what is certified today and what is not. We do not publish aspirational dates that we may miss. We do publish, in detail, the controls that are in place in lieu of those certifications, and we welcome customer audits of those controls under reasonable scoping.
>
> — Lucas Neves, Founder & CEO, Synapse Inovação e Tecnologia LTDA.

## 7. Change history

| Version | Date       | Change               |
| ------- | ---------- | -------------------- |
| 1.0     | 2026-06-21 | Initial publication. |

When a certification status changes (audit started, audit completed, scope expanded), this table is updated and subscribers to [subprocessors@graphorlm.com](mailto:subprocessors@graphorlm.com) receive an email.

## Contact

* Compliance, audit, and certification inquiries: [privacy@graphorlm.com](mailto:privacy@graphorlm.com)
* Subscription to compliance-status change notifications: [subprocessors@graphorlm.com](mailto:subprocessors@graphorlm.com)
* Customer support: [support@graphorlm.com](mailto:support@graphorlm.com)
