erp.io
Pricing
Log inBook a demo
HomeTrustCompliance

Trust

Compliance

This page states where we stand, including the certifications we do not hold. A compliance page that lists only achievements is a marketing page, and any buyer running a real vendor review will find the gaps in twenty minutes anyway.

Effective
August 18, 2026
Last updated
August 18, 2026
Entity
Nead, LLC (d/b/a DEV.co)

Contents

  1. 01Current status, including the gaps
  2. 02Controls in place regardless of certification
  3. 03Financial reporting standards
  4. 04Security reviews and questionnaires
  5. 05The risk we cannot certify away
  6. 06Contact

Questions about this policy?

Nead, LLC (d/b/a DEV.co)
1425 Broadway 22689
Seattle, WA 98112
United States

[email protected]

01Current status, including the gaps

FrameworkStatusDetail
SOC 2 Type IINot yet heldControls are designed against the Trust Services Criteria. We have not completed an observation period or received a report. We will not claim otherwise.
SOC 2 Type INot yet heldPlanned ahead of Type II.
ISO 27001Not heldNot currently planned. If a customer requires it we will say so rather than implying a timeline.
GDPR / UK GDPRCompliant as processorDPA available, Article 28 terms with subprocessors, SCCs and UK Addendum for transfers.
CCPA / CPRA and US state lawsCompliant as service providerNo sale or sharing of personal information. GPC honoured. Rights process published.
PCI-DSSOut of scopeWe never handle card data. Payment processing is performed by a PCI-compliant processor.
HIPAANot a covered entityWe do not process PHI. Healthcare customers connect financial rather than clinical data. BAA available where counsel requires one.

If SOC 2 Type II is a hard procurement requirement today, we do not meet it. Tell us early and we will say so plainly rather than proposing a workaround. Some buyers can proceed on a security review and contractual commitments; others cannot, and that is a legitimate position.

02Controls in place regardless of certification

Certification attests that controls exist and operate. The controls themselves are what protect your data, and they exist now.

  • Access control enforced in the data layer. Every query carries an actor and a scope; a query without them fails rather than returning the wrong rows. Row-level security in the database sits underneath as defence in depth.
  • One permission model for every actor. People, agents, API credentials, and portal users are governed identically, so automated activity cannot fall outside the control framework.
  • Append-only, hash-chained audit log. No actor, including our engineers, has an update or delete path. Alteration or removal is detectable.
  • Break-glass production access. Time-bound, dual-approved, logged into the same audit trail, and reported to affected customers. Routine support does not include production data access.
  • Encryption. TLS 1.2 or higher in transit; encryption at rest.
  • Segregation of duties. Conflicting authority combinations are rejected at grant time rather than reported afterwards.
  • Tested recovery. Restores exercised quarterly against production-sized data. RPO 5 minutes, RTO 4 hours for regional failure.
  • Vendor review. Security assessment before engaging any subprocessor that touches Customer Data.

03Financial reporting standards

A question we are asked in most evaluations: is the software itself compliant with accounting standards? The honest answer has two parts.

Software does not make financial statements compliant. Preparation of financial statements in accordance with US GAAP or IFRS is the responsibility of your management and your accountants. No system can discharge that.

What we do provide is a ledger and control environment that supports it:

  • double-entry, append-only accounting with corrections posted as reversals;
  • revenue recognition supporting ASC 606 five-step treatment, with performance obligations, allocation, and the basis for each determination recorded;
  • lease treatment inputs, accruals, prepaid amortisation, and period-close controls;
  • multi-entity consolidation with transaction-level intercompany elimination and computed cumulative translation adjustment rather than a plug;
  • an audit trail covering automated as well as human actions, which is what makes automated activity assertable; and
  • read-only, scoped, expiring auditor access with its own logged activity.

Where a determination requires judgement — whether an obligation is distinct, whether a cost is capitalisable — the system records the determination and who made it. It does not make it for you, and an agent is not permitted to.

04Security reviews and questionnaires

We complete security questionnaires and participate in vendor reviews. Write to [email protected] and we will turn most around within five business days.

Available on request, under NDA where appropriate:

  • a security overview describing architecture, controls, and data flows;
  • our Data Processing Addendum, including SCCs and the UK Addendum;
  • subprocessor list with locations and processing purposes;
  • incident response and breach notification commitments;
  • business continuity and disaster recovery summary, with tested RPO and RTO; and
  • penetration test summary, where a current test exists.

Where a questionnaire asks whether we hold a certification we do not hold, we answer no. We do not answer “in progress” unless an engagement is actually underway with a named auditor.

05The risk we cannot certify away

The honest risk in buying from us is not a control failure. It is that we are a young company and you would be running finance operations on our software.

No certification addresses that. What addresses it is that a complete, current copy of your data sits in storage you control, produced automatically on a schedule you set, in open documented formats, including the audit trail. If we cease to exist, you hold a dataset a competent team can load elsewhere.

We recommend exercising that export during evaluation rather than after signing. Ask for a sample against a demo tenant, load it somewhere, and judge whether it is what you would need. Reluctance from any vendor to let you do that is itself informative.

Source code escrow is available on applicable plans. We say plainly that escrowed code without infrastructure or operational knowledge is worth considerably less than most buyers assume, and that the data is the asset worth protecting.

06Contact

For compliance documentation, questionnaires, or to discuss a requirement we do not currently meet, write to [email protected].

Nead, LLC (d/b/a DEV.co), 1425 Broadway 22689, Seattle, WA 98112, United States.

erp.io

ERP software with AI agents inside it — and the implementation, integration, and custom development that make it fit how you already work. We research and compare the rest of the market too, including the products we compete with.

AI
  • AI agents
  • ERP Copilot
  • Governance
  • Authority levels
  • Accuracy method
  • AI in ERP report
Platform
  • General ledger
  • Shadow ledger
  • Close
  • Reporting
  • Customer portals
  • API & MCP
Services
  • Implementation
  • Implementation rescue
  • Integration
  • Migration
  • Custom modules
  • Pricing
Research
  • ERP directory
  • Comparisons
  • Free tools
  • Guides
  • Glossary
  • Methodology
Company
  • About
  • Editorial policy
  • Partners
  • Trust center
  • Careers
  • Contact
© 2026 erp.io — a product of Nead, LLC (d/b/a DEV.co)We rank competitors honestly. No paid placement, ever.LegalPrivacyTermsDPASLACookiesStatus