01The register
Organized the same way the trust center itself is: reliability, regulatory compliance, data privacy, and platform security. Every document below carries its own draft banner on its own page — the status column here is a summary, not a separate assertion.
Availability
| DOCUMENT | STATUS |
|---|---|
| Availability | DRAFT |
| Business continuity | DRAFT |
| Incident response | DRAFT |
| Service level agreement | DRAFT |
| Support | DRAFT |
Compliance
| DOCUMENT | STATUS |
|---|---|
| Compliance | DRAFT |
| Accessibility conformance | DRAFT |
| AI-disclosure law | DRAFT |
| CCPA | DRAFT |
| GDPR | DRAFT |
| PCI DSS | DRAFT |
| State recording law | DRAFT |
| TCPA | DRAFT |
Privacy
| DOCUMENT | STATUS |
|---|---|
| Privacy | DRAFT |
| AI training | DRAFT |
| Caller data | DRAFT |
| Data residency | DRAFT |
| The DPA, explained | DRAFT |
| Retention | DRAFT |
| Rights request | DRAFT |
| Subprocessors | DRAFT |
Security
| DOCUMENT | STATUS |
|---|---|
| Security posture | DRAFT |
| Access control | DRAFT |
| Encryption | DRAFT |
| Infrastructure | DRAFT |
| Logging | DRAFT |
| Payment security | DRAFT |
| Development practices | DRAFT |
| Vulnerability disclosure | DRAFT |
| Security whitepaper | DRAFT |
02Certifications and audits
Stated directly, because a vendor-risk review asks for this specifically and a missing row would read as an oversight rather than an honest answer:
| ITEM | STATUS |
|---|---|
| SOC 2 (Type I or II) | None held. No audit has been performed — no report, scope, period, or exceptions list exists. |
| ISO 27001 or similar | None held. |
| PCI DSS attestation | Not applicable in the ordinary sense — Dohos is designed to stay out of PCI scope for card data entirely rather than hold an attestation for handling it. See the PCI position. |
| Independent penetration test | None performed. No cadence, scope, or findings exist to share. |
| Accessibility conformance (VPAT / ACR) | None held. WCAG 2.2 Level AA is the engineering target — see accessibility conformance. |
| Certificate of insurance | None issued. No commercial insurance policy is currently bound, so there is no carrier, limit, or certificate to provide. |
03Subprocessors
The approved subprocessor register is currently empty — zero rows. That is an accurate statement about which vendors have cleared Dohos's diligence process for public listing as a subprocessor, not a statement that no infrastructure is used.
Separately, and on a different claim entirely, the infrastructure a restaurant's own reviewer would reasonably ask about is named directly: database, authentication, and backend hosting are disclosed as infrastructure. Being named as infrastructure is not the same thing as being an approved subprocessor — that status requires its own completed review, and no vendor, including the infrastructure named there, has cleared it yet. See subprocessors for the full distinction and how a vendor would earn a row.
04Legal library
The contracts and public notices behind the trust pages above — the versions a restaurant would actually sign or a caller would actually be shown, once any of this is approved and effective.
| DOCUMENT | CATEGORY | STATUS |
|---|---|---|
| Website and Diner Terms | Public terms | DRAFT |
| Privacy Notice | Public notice | DRAFT |
| Acceptable Use Policy | Public policy | DRAFT |
| AI and Voice Transparency Notice | Public notice | DRAFT |
| SMS and Communications Notice | Public notice | DRAFT |
| Order, Payment, Refund, and Dispute Notice | Public notice | DRAFT |
| Privacy Rights Request Notice | Public notice | DRAFT |
| Product Claims and Service Limitations | Public notice | DRAFT |
| Cookie and Tracking Notice | Public notice | DRAFT |
| Accessibility Statement | Public statement | DRAFT |
| Subprocessor List and Change Notice | Public register | DRAFT |
| Restaurant Services Agreement | Contract | DRAFT |
| Data Processing Addendum | Contract | DRAFT |
| Service Level and Support Schedule | Contract schedule | DRAFT |
| Vendor and Subprocessor Terms | Contract — vendor-facing | DRAFT |
| Version Archive | Register | DRAFT |
05Requesting more
A document this packet doesn't yet publish — a specific evidence request, a diligence questionnaire, or a follow-up on anything above — can be sent to /contact/security. That is the current intake for this packet; it is not a staffed, dedicated compliance desk, the same honest limit stated throughout this trust center.