Which rules your product actually has to meet
Four names come up in almost every intake call. Most founders have heard all of them and are sure about none. Here is what each one means for the thing you are building.
Rules follow your users, your data and your buyers — not your company address. That is the whole trick. Answer three questions honestly and the list usually writes itself: where do your users live, what do you store about them, and who has to approve buying your product.
GDPR
European privacy law. It applies the moment you hold personal details about someone in Europe or the UK — a name, an email address, an IP address, a record of what they did in your product. It is not a certificate you earn; it is a set of promises you keep: collect only what you need, say why you hold it, delete it when someone asks, and be able to show who accessed it.
SOC 2
An American report, written by an auditor, that says your company does what it claims about security. Nobody needs it to launch. You need it the first time a larger customer sends a security questionnaire — which is usually the same week you are trying to close them. Building for it early costs very little; retrofitting it mid-deal costs a quarter.
HIPAA
Rules for health information in the United States. If your product touches symptoms, diagnoses, prescriptions or therapy notes, it applies. In practice it means tight access control, a permanent record of who looked at what, encryption everywhere, and signed agreements with anyone who stores the data for you.
ISO 27001
The international equivalent of the trust SOC 2 buys you. Outside the United States, buyers usually ask for this one. It certifies the way your company manages security, not a single product.
| If this is true | Expect to meet |
|---|---|
| Your users are in Europe or the UK and you store anything personal | GDPR |
| You handle health or medical information | HIPAA |
| You sell to larger companies in the US | SOC 2 |
| You sell to larger companies elsewhere | ISO 27001, often with SOC 2 |
| You hold card details yourself instead of using Stripe | Card industry rules — usually avoidable |
| None of the above yet | Nothing formal, but build as if it is coming |
Common questions
Can we decide this later?
You can decide the paperwork later. You cannot decide the foundations later without redoing work — access control, audit trails and where data lives are all cheaper to get right the first time.
What if we pick the wrong one?
Nothing breaks. The intake answer tells your engineer how strict to be; your Key Account Manager revisits it on the intro call once we understand your customers.
More on this: Production architecture & security
Built something in Lovable you want people to rely on?
We are the engineers who take it the rest of the way — secured, tested, released and supported.