Compliance
Last updated: July 2026
Mabstack maintains compliance with major global standards and regulations. We embed compliance into our delivery lifecycle rather than treating it as an afterthought, ensuring every engagement meets the required regulatory framework.
SOC 2 Type II
Our controls for security, availability, and confidentiality are audited annually by an independent CPA firm against SOC 2 criteria.
GDPR
We comply with the General Data Protection Regulation for all processing of EU personal data. Data Processing Agreements are available on request.
ISO 27001
Our Information Security Management System (ISMS) is aligned with ISO/IEC 27001 standards, governing policy, risk assessment, and continuous improvement.
Regulatory Alignment
Our practices align with PCI DSS, HIPAA, and Bangladesh's Data Protection Act. We adapt to client-specific regulatory requirements per engagement.
Audit & Reporting
Compliance documentation, audit reports, and Data Processing Agreements are available to enterprise clients under NDA. We also support customer-led audits with reasonable advance notice. Contact compliance@mabstack.com for requests.
Subprocessors
We maintain a current list of subprocessors involved in service delivery. Clients are notified of any changes at least 30 days in advance. Our subprocessors are vetted against the same security and compliance standards we apply internally.
