generated: '2026-07-18' method: searched source: >- https://bettermode.com/security and https://developers.bettermode.com/docs/guide/graphql/ — compliance program from the security page; technical conformance derived from the documented GraphQL surface. description: >- Standards and compliance posture Bettermode conforms to. Security/compliance claims are published on the security page (SOC 2 Type II, ISO 27001, GDPR, CCPA); technical conformance is derived from the documented GraphQL API behaviors. standards: - id: graphql conforms: true evidence: Public API is GraphQL (single POST endpoint, introspectable schema, @deprecated directives). - id: relay-cursor-pagination conforms: true evidence: List fields use Relay-style connections (edges/nodes, pageInfo, cursors). - id: webhooks conforms: true evidence: Signed (X-Tribe-Signature) HTTP POST webhook delivery with challenge verification. - id: oauth2 conforms: false evidence: Uses bearer App/Member access tokens, not a documented OAuth2 authorization-server flow. - id: rfc9457-problem-details conforms: false evidence: Errors use the standard GraphQL errors[] envelope, not application/problem+json. - id: soc2-type-ii conforms: true evidence: "Security page: SOC 2 Type II certified." - id: iso-27001 conforms: true evidence: "Security page: ISO 27001 certified data centers." - id: gdpr conforms: true evidence: "Security page: GDPR compliant." - id: ccpa conforms: true evidence: "Security page: CCPA compliant." compliance_program: certifications: [SOC 2 Type II, ISO 27001, GDPR, CCPA] page: https://bettermode.com/security encryption: 256-bit encryption in transit and at rest practices: [external penetration testing, SIEM intrusion detection, network ACLs]