Trust CenterCompliance

Certified Across
Every Jurisdiction

Harch Corp maintains compliance with international and regional standards across Moroccan, European, African, and global jurisdictions. Every certification is independently audited and continuously maintained.

Full Certification Portfolio

Each certification represents an independent, third-party validation of our security and operational controls.

SOC 2 Type II

System and Organization Controls 2 Type II

Achieved

Independent audit of our security, availability, and confidentiality controls over a minimum 6-month observation period. Demonstrates continuous operational effectiveness.

Scope

HarchOS Platform, Harch Intelligence Infrastructure

Region

Global

Auditor

Deloitte & Touche

Last Audit

Nov 2025

ISO 27001

ISO/IEC 27001:2022

Achieved

International standard for information security management systems (ISMS). Certified across all Harch Corp operating entities and data center facilities.

Scope

All Harch Corp S.A. Operations

Region

Global

Auditor

Bureau Veritas

Last Audit

Sep 2025

ISO 22301

ISO 22301:2019 Business Continuity

Achieved

Business continuity management system certification ensuring Harch Corp maintains critical operations during disruptions, with tested recovery procedures.

Scope

All Harch Corp S.A. Operations

Region

Global

Auditor

Bureau Veritas

Last Audit

Oct 2025

GDPR

EU General Data Protection Regulation

Achieved

Full compliance with EU data protection regulation for all processing of EU data subjects. Includes DPA availability, cross-border transfer mechanisms, and data subject rights fulfillment.

Scope

All services processing EU personal data

Region

EU

Last Audit

Ongoing

CCPA

California Consumer Privacy Act

Achieved

Compliance with California privacy requirements for US-based data subjects, including right to know, delete, and opt-out of data sale.

Scope

Services offered to California residents

Region

US

Last Audit

Ongoing

Moroccan DPA

Moroccan Law 09-08 (Data Protection Act)

Achieved

Compliance with Moroccan data protection law administered by the CNDP (National Commission for Personal Data Protection). All data processing declared and registered.

Scope

All Harch Corp S.A. Morocco operations

Region

Morocco

Auditor

CNDP Morocco

Last Audit

Jun 2025

ISO 27017

ISO/IEC 27017:2015 Cloud Security

In Progress

Cloud-specific security controls extending ISO 27001. Covers cloud service shared responsibility, virtual network security, and cloud tenant isolation.

Scope

HarchOS Cloud Platform

Region

Global

Last Audit

Pending

ISO 27018

ISO/IEC 27018:2019 PII in Public Cloud

In Progress

Protection of personally identifiable information in public clouds. Establishes controls for data processing, breach notification, and data subject rights in cloud environments.

Scope

HarchOS Cloud Platform

Region

Global

Last Audit

Pending

PCI DSS

Payment Card Industry Data Security Standard

In Progress

Security standard for organizations that handle credit card data. Ensures secure payment processing across Harch Corp billing and partner transactions.

Scope

Billing, payment processing systems

Region

Global

Last Audit

Pending

CSA STAR Level 2

Cloud Security Alliance STAR Level 2

In Progress

Third-party audit of cloud security controls against CSA Cloud Controls Matrix. Demonstrates transparency and rigorous cloud security practices.

Scope

HarchOS Cloud Platform

Region

Global

Last Audit

Pending

HITRUST CSF

HITRUST Common Security Framework

Planned

Comprehensive security framework for healthcare and life sciences. Required for Harch Corp health-tech partnerships and medical data processing.

Scope

Health-tech vertical operations

Region

Global

Last Audit

Pending

FedRAMP

Federal Risk and Authorization Management Program

Planned

US government cloud authorization program. Enables Harch Corp to serve US federal agencies and government contractors with sovereign cloud services.

Scope

HarchOS US Region (planned)

Region

US

Last Audit

Pending

Compliance by Region

Harch Corp operates across multiple jurisdictions, each with specific regulatory requirements. Our compliance program is designed for multi-jurisdictional coverage.

🇲🇦

Morocco

Regional Compliance Program

Primary operating jurisdiction. Full compliance with Moroccan Law 09-08, CNDP registration, and all local regulatory requirements.

Active Certifications

Moroccan DPA
ISO 27001
SOC 2 Type II
ISO 22301
🇪🇺

European Union

Regional Compliance Program

GDPR compliance for EU data subjects. Standard contractual clauses for data transfers. Adequacy decision alignment for Morocco-EU transfers.

Active Certifications

GDPR
ISO 27001
SOC 2 Type II
ISO 22301
🌍

Africa

Regional Compliance Program

Alignment with emerging African data protection frameworks including Cote d'Ivoire, Kenya, South Africa, and Nigeria regulations.

Active Certifications

ISO 27001
SOC 2 Type II
ISO 22301
GDPR (as baseline)
🌐

Global

Regional Compliance Program

International compliance programs for cross-border operations. Designed to meet the most stringent requirements across all operating jurisdictions.

Active Certifications

SOC 2 Type II
ISO 27001
ISO 22301
CCPA
PCI DSS (In Progress)

Documentation Available

Qualified customers and partners can request access to audit reports, certificates, and compliance documentation through our secure document portal.

DocumentPeriodAuditorTypeAccess
SOC 2 Type II Report
May 2025 — Nov 2025Deloitte & ToucheAudit Report
ISO 27001 Certificate
Sep 2025 — Sep 2026Bureau VeritasCertificate
ISO 22301 Certificate
Oct 2025 — Oct 2026Bureau VeritasCertificate
Penetration Test Summary
Q4 2025NCC GroupTest Report
Cloud Security Assessment
Q3 2025NCC GroupAssessment
GDPR DPIA Summary
OngoingInternal DPOAssessment
CNDP Registration
Jun 2025CNDP MoroccoRegistration
Business Continuity Test Results
Q3 2025Internal AuditTest Report

Standard DPA Available

Our pre-signed Data Processing Agreement is available for all customers. It covers GDPR Article 28 requirements, sub-processor management, breach notification procedures, and data subject rights assistance.

GDPR Article 28 compliant processing terms

Sub-processor notification and management

72-hour breach notification commitment

Data subject rights assistance (access, deletion, portability)

Cross-border transfer safeguards (SCCs)

Moroccan Law 09-08 alignment

DPA Quick Reference

Governing LawMoroccan Law / GDPR
Data ControllerCustomer
Data ProcessorHarch Corp S.A.
Sub-processorsListed in Annex I
Breach Notification72 hours
Audit RightAnnual, with notice
Data DeletionWithin 30 days of termination
Cross-Border TransferSCCs + BCRs

Need Compliance Documentation?

Our compliance team can provide specific audit reports, certificates, and documentation for qualified requests.