GDPR + DPA
Standard Data Processing Agreement, EU data residency option, sub-processor list and DSR workflow.
Available today
Onboarding progress
0 / 22 tasks
Zanyar
0 of 22 tasks
Trust & Security
Telepathy handles employee data on day one, so security is a feature, not an afterthought. Here's exactly where we are on the certifications buyers like Klarna, Spotify and mid-market tech companies ask for — and when each one lands.
Standard Data Processing Agreement, EU data residency option, sub-processor list and DSR workflow.
Available today
Point-in-time attestation of security controls. Required by most US mid-market and enterprise buyers.
Audit in ~6–10 weeks
Continuous control evidence over a 3–12 month window. Klarna, Spotify and similar buyers expect this for production data.
6–9 months after Type I
International ISMS certification. Strongly preferred by EU enterprises and procurement teams in the Nordics.
9–12 months
SOC 2 Type I + II
$25k–$60k
Year-1 audit, automation tooling (Vanta / Drata / Secureframe), policy work.
ISO 27001
$35k–$120k
3-year cycle including Stage 1 + Stage 2 audit and surveillance.
Typical timeline
6–12 mo
From first policy commit to a signed Type II report a buyer can forward to their CISO.
Need a signed NDA, DPA, pen-test letter, or our trust packet? Email security@telepathy.example.
Assistant
Telepathy AI
Ask about setup, missions, documents, or what to do next. Answers stay concise.