Trust & Compliance

We prove our compliance, too.

Sightline helps you prove your compliance — so we hold ourselves to the same standard, and we run Sightline on Sightline. Here is exactly how we protect your data, and where we stand against every framework we help you assess. We label status honestly and never claim a certification we don't hold.

How we protect your data

The foundation every framework rests on

Status legend

Aligned — built and operated to meet it; evidenced internally. Self-attested — assessed ourselves; no third-party audit yet. On roadmap — external certification planned; we'll publish it when earned.

Framework-by-framework

NIST CSF 2.0Aligned

Govern, identify, protect, detect, respond, recover across our own systems.

Our internal program is structured on CSF 2.0 — the same spine we assess you against.

GDPRAligned

Lawful processing, data-subject rights, security of processing (Art. 32), 72-hour breach notice.

Data minimization, encryption, access controls, export/erasure, and a breach process are in place. DPA available.

HIPAAAligned

Administrative, physical, and technical safeguards for ePHI; BAAs.

Encryption, access control, audit controls, and a Business Associate Agreement are available for healthcare customers.

SOC 2Self-attested

Independent attestation of trust-services controls.

We run continuous self-assessment today; an external Type II audit is on the roadmap.

ISO/IEC 27001Aligned

A certified Information Security Management System.

Our ISMS follows 27001; accredited certification is on the roadmap.

FERPAAligned

Protect student education records; reasonable safeguards; disclosure limits.

For education customers: data is minimized, encrypted, access-controlled, and never used beyond providing the service.

PCI DSSOut of scope

Protect cardholder data.

Sightline never stores cardholder data — payments run through a PCI-certified processor. We never touch card numbers.

CMMC 2.0On roadmap

Protect FCI/CUI for defense work.

Relevant only for defense customers; we do not claim CMMC certification today.

Cyber Essentials (UK)Self-attested aligned

Firewalls, secure config, patching, access control, malware protection.

These five controls are in place across our systems.

Essential Eight (AU)Aligned

Eight mitigation strategies (MFA, patching, backups, least privilege).

MFA, patching, least-privilege admin, and regular backups are enforced.

NIS2 (EU)Aligned

Risk management and incident reporting for in-scope entities.

Risk management, supply-chain diligence, and incident handling are in place.

DPDP (India)Aligned

Lawful processing of digital personal data; security safeguards; breach notice.

Consent/notice handling, security safeguards, and a breach process for data principals in India.

PDPA (Malaysia)Aligned

Seven personal-data principles incl. security and retention.

Security, retention, and access principles are implemented for Malaysian data.

How to vet us

Proof you can ask for

We back every status above with evidence. To vet Sightline, request or download:

Read the Data Protection Policy Request the trust pack

Sightline is hosted on Cloudflare — encrypted and region-configurable, with data residency available for international customers. Questions? Get in touch.

This statement reflects our posture as of 2026-06-07 and is updated as our program matures. It describes alignment and, where stated, self-attestation; externally-audited certifications are labeled “on roadmap” until earned. It is provided for transparency and is not a warranty.

Want the details?

Request our DPA, security whitepaper, or latest self-assessment — generated by Sightline, of Sightline.