dohosGet started
PLATE Nº 069 · DOCUMENT

Vendor packet

TARGET-STATE DRAFT — NOT APPROVED OR EFFECTIVE
STATUSTarget-state draft
LAST REVIEWEDNone yet — no review has run
CONTACTvia /contact/security
DRAFT NOTICEThis page is a map, not a new claim: it gathers every Dohos trust and legal document into one register with its current status and a link. Every document it points to is a target-state draft — none has been approved, reviewed, or made effective — and this page does not state anything about Dohos's posture that the linked page doesn't already state itself. Where something genuinely doesn't exist yet, this page says so directly rather than omitting the row.

01The register

Organized the same way the trust center itself is: reliability, regulatory compliance, data privacy, and platform security. Every document below carries its own draft banner on its own page — the status column here is a summary, not a separate assertion.

Availability

Compliance

Privacy

Security

02Certifications and audits

Stated directly, because a vendor-risk review asks for this specifically and a missing row would read as an oversight rather than an honest answer:

ITEMSTATUS
SOC 2 (Type I or II)None held. No audit has been performed — no report, scope, period, or exceptions list exists.
ISO 27001 or similarNone held.
PCI DSS attestationNot applicable in the ordinary sense — Dohos is designed to stay out of PCI scope for card data entirely rather than hold an attestation for handling it. See the PCI position.
Independent penetration testNone performed. No cadence, scope, or findings exist to share.
Accessibility conformance (VPAT / ACR)None held. WCAG 2.2 Level AA is the engineering target — see accessibility conformance.
Certificate of insuranceNone issued. No commercial insurance policy is currently bound, so there is no carrier, limit, or certificate to provide.
NOTEThe security whitepaper describes Dohos's actual controls directly, without a certification claim attached to any of them — reading it is the alternative to a report that doesn't exist yet.

03Subprocessors

The approved subprocessor register is currently empty — zero rows. That is an accurate statement about which vendors have cleared Dohos's diligence process for public listing as a subprocessor, not a statement that no infrastructure is used.

Separately, and on a different claim entirely, the infrastructure a restaurant's own reviewer would reasonably ask about is named directly: database, authentication, and backend hosting are disclosed as infrastructure. Being named as infrastructure is not the same thing as being an approved subprocessor — that status requires its own completed review, and no vendor, including the infrastructure named there, has cleared it yet. See subprocessors for the full distinction and how a vendor would earn a row.

05Requesting more

A document this packet doesn't yet publish — a specific evidence request, a diligence questionnaire, or a follow-up on anything above — can be sent to /contact/security. That is the current intake for this packet; it is not a staffed, dedicated compliance desk, the same honest limit stated throughout this trust center.