SOC 2 Type II
Enterprise

Workspace settings

Trust UX starters: roles, retention, and policy cues. Wire to RBAC + audit logging later.

RBAC (planned)
AuditLog (planned)
Retention controls (planned)

Workspace

Basic metadata (placeholder).

Data retention

Enterprise trust cue (placeholder).

Uploads
Keep raw artifacts for X days.
Draft
Audit logs
Keep audit events for Y days.
Policy
Note: retention configuration should be immutable-audited and role-gated.

Security posture

Surface trust cues in-context.

Policy: No training on customer data
Keep this visible in product UX and in your security page.
View security page