Compliance and certifications — CTD Guide

Compliance and certifications

CTD meets or exceeds standard enterprise compliance requirements. Here's what we're certified for and how we handle specific regulatory frameworks.

SOC 2 Type II

CTD is independently audited against the SOC 2 Type II standard, covering the Trust Services Criteria for Security, Availability, and Confidentiality. Audits are conducted annually by a third-party auditor.

Unlike SOC 2 Type I (which certifies controls exist at a point in time), Type II certification verifies that those controls operated effectively over a sustained period. Enterprise customers can request our SOC 2 report by contacting security@ctd.ai.

GDPR

CTD complies with the General Data Protection Regulation (GDPR) for users in the EU and EEA. Your rights under GDPR include:

CCPA

CTD complies with the California Consumer Privacy Act (CCPA) for California residents. We honor all CCPA rights including the right to know what personal information is collected, the right to delete, and the right to opt out of the sale of personal information (we do not sell personal data).

You can submit a CCPA request via our CCPA request form.

Enterprise security reviews

We regularly answer security questionnaires for enterprise customers. Our team is happy to:

Contact security@ctd.ai to start the process. We typically turn around questionnaires within 5 business days.

Have a question or running into an issue? Email us at support@ctd.ai — we're happy to help.