PCI DSS Level 1
InheritedAll credit card capture and processing occurs inside Stripe, certified PCI DSS Level 1 — the highest level of the standard. Modari never receives or stores PAN data; we only retain a referenced token and the last 4 digits for display.
SOC 2 Trust Services Criteria
AlignedOur controls for security, availability, processing integrity, confidentiality, and privacy are designed in line with the Trust Services Criteria published by AICPA. We are prepared to undergo a SOC 2 Type II audit when contractually required.
ISO/IEC 27001
AlignedWe apply the relevant Annex A domains: access control (A.9), cryptography (A.10), operations security (A.12), incident management (A.16), and compliance (A.18). The framework guides our internal information security policy.
GDPR (EU)
CompliantWe comply with Regulation (EU) 2016/679: documented legal bases, record of processing activities, data subject rights, breach notification within 72 hours, international transfers via Standard Contractual Clauses, and a Data Processing Agreement (DPA) available upon request.
UK GDPR + ICO
CompliantWe apply the United Kingdom regime in accordance with Information Commissioner's Office (ICO) guidance, with treatment equivalent to GDPR for data subjects resident in the UK.
Habeas Data — Law 1581/2012 (Colombia)
CompliantWe comply with Law 1581 of 2012 and Decree 1377 of 2013. We handle requests, queries, and complaints within statutory timelines (15 business days for queries, 15 business days for complaints) through our PQRs channel.
CCPA / CPRA (California)
CompliantWe honor rights granted by the California Consumer Privacy Act and its CPRA amendment: right to know, delete, correct, opt-out of sharing, and not be discriminated against. We automatically respect the Global Privacy Control (GPC) browser signal.
LGPD (Brazil)
CompliantWe apply the Lei Geral de Proteção de Dados with documented legal bases, data subject rights, and Chapter V mechanisms for international transfers to jurisdictions without adequate level.
OWASP Application Security Verification Standard
AlignedOur development lifecycle is guided by the OWASP ASVS and OWASP Top 10 recommendations: input validation at boundaries, output encoding, secure session management, approved cryptography, and least privilege.
WCAG 2.1 Level AA
In progressWe aspire to Web Content Accessibility Guidelines 2.1 Level AA. We audit contrast, keyboard navigation, semantic markup, and screen reader compatibility on every release.