Trust — Compliance

Compliance

The standards MetaDev aligns to — and how we help customers meet theirs — across data protection, security, and sector regulation in India and beyond.

Last updated — 28 August 2026MetaDev Innovations Pvt. Ltd.

Need help?

Questions about these terms? Our support team replies within 24 hours.

Frameworks and safeguards

Compliance at MetaDev is design-led and evidence-based. We map controls once to multiple frameworks so customers inherit coverage without duplicate work — security, privacy, and availability share the same control set, tested continuously.
  • ISO 27001
  • ISO 9001
  • ISO 42001
  • SOC 2
  • HIPAA safeguards
  • PCI DSS
  • GDPR

1. Our approach

Compliance at MetaDev is design-led and evidence-based. We map controls once to multiple frameworks so customers inherit coverage without duplicate work — security, privacy, and availability share the same control set, tested continuously.

This page is informational; binding commitments are in your order form, DPA, and product addenda. We update our posture as laws and standards evolve and publish material changes here.

2. Certifications & attestations

MetaDev certifications and attestations
StandardScopeStatus
ISO/IEC 27001:2022Information security management — MetaDev platform & operationsCertified — statement of applicability on request
ISO 9001:2015Quality management for design, build, and supportCertified
ISO/IEC 42001:2023AI management system (MetaAds, MetaCheck, MetaHire AI features)Certified — AI governance & risk
SOC 2 Type IISecurity, Availability, ConfidentialityAttested — report available under NDA
HIPAA safeguardsAdministrative, physical, technical safeguards for MetaHealthImplemented — BAA available
PCI DSS v4.0Card-data flows via MetaCard / MetaLedger (service-provider scope)Assessed — AoC on request
GDPREU/UK personal data processed via any productAligned — SCCs & ROPA maintained

Copies or summaries are available under NDA via business@metadev.in.

3. India — DPDP Act & IT Act

As a Data Fiduciary under the Digital Personal Data Protection Act, 2023 and a body corporate under the IT Act, 2000 (SPDI Rules), we:

  • Process personal data only for a specified, lawful purpose with consent / legitimate use and clear notice.
  • Maintain reasonable security practices, breach-notification readiness, and Data Protection Officer & grievance redressal (see Privacy Policy).
  • Honour data-principal rights — access, correction, erasure, grievance redressal, and nomination — within statutory timelines.
  • Impose DPDP-aligned obligations on Data Processors via contract, with audit rights and sub-processor transparency.
  • Data-retention, localisation, and transfer requirements are addressed per product DPA, consistent with Government notifications as they come into force.

4. Global privacy

For customers or data subjects in the EU/UK and other regions we apply GDPR principles: lawfulness, purpose limitation, minimisation, accuracy, storage limitation, integrity, and accountability. Transfers outside India/EU use approved mechanisms (SCCs / IDTA) with supplementary measures, and we maintain a Record of Processing Activities (ROPA).

5. Sector requirements

Sector-specific compliance considerations
Product / domainConsiderations
MetaHealth (care)HIPAA safeguards, consent for health data, audit trails; not a substitute for professional medical advice.
MetaEdu (learning)FERPA-aligned access controls, child-privacy guardrails, and institution-configured retention.
MetaCheck / MetaHire (verification & hiring)Lawful basis & candidate notice before checks; human review for adverse actions; data minimisation and purpose limitation.
MetaLedger / MetaCard / MetaAds (finance & payments)PCI DSS for card data, GST/tax record-keeping alignment, and spend-control policies.
AI features (across suite)ISO 42001 AI governance — risk assessment, data quality, bias testing, human oversight, and logging.

Sector content does not constitute legal advice — customers remain responsible for their own regulatory obligations.

6. How we comply, day to day

  • Policies & training: Written ISMS, privacy, and AI-governance policies; annual workforce training and role-specific refreshers.
  • Risk & audit: Annual risk assessment, quarterly control testing, internal audit, and management review; external audits for ISO/SOC 2.
  • Vendor management: Due diligence, DPAs / SCCs, and annual reviews for sub-processors (list available on request).
  • Secure development: Threat modelling, SAST/DAST, dependency scanning, and independent pentests (see Security).
  • Incident readiness: Documented response plans, tabletop exercises, and breach-notification playbooks.

Shared responsibility

We secure the platform; customers secure their use — including access provisioning, lawful basis, and end-user notices. Product docs call out customer responsibilities per feature.

7. What customers can expect from us

  • A signed Data Processing Agreement (and SCCs / BAA where needed) before production processing.
  • Transparent sub-processor and region information with change notice.
  • Audit support: Reports under NDA, questionnaire responses, and — for enterprise — on-site/virtual audit rights per contract.
  • Timely security advisories for customer-actionable issues.

Need another policy? Privacy Policy · Terms of Service.