boundlesstelecom
Boundless 2.0
Regulatory & Compliance

Compliance is a property, not a project.

Boundless treats every regulation in the telecoms and data-protection canon as a continuous, machine-verifiable property of the platform - not an annual scramble for paperwork.

26/26 layers activeLast updated · May 2026UK + EU sovereign
Posture at a glance

Six headline frameworks, always green.

Status reflects the live posture of the platform. Certification milestones for ISO 27001, SOC 2 and PCI-DSS run alongside a continuous-evidence operating model - we don't wait for an annual audit to know where we stand.

NIS2
EU 2022/2555
Implemented
Last evidence · Continuous
DORA
EU 2022/2554
Implemented
Last evidence · Continuous
GDPR Art.32
EU 2016/679
Implemented
Last evidence · Continuous
ISO 27001:2022
Annex A - implemented as code
Aligned · cert Q3 2026
Last evidence · Q1 2026 audit
PCI-DSS v4.0
Cardholder data scope
Aligned · attest Q4 2026
Last evidence · Q4 2025 self-assess
SOC 2 Type II
Trust services criteria
Aligned · cert Q1 2027
Last evidence · In flight
Frameworks · what we follow & exceed

24 regimes.
One cognitive substrate.

Each card shows the rule, the industry default response, our answer, and where we exceed. Click any card to expand. All entries reflect publicly documented regulatory text as of May 2026.

Sovereign UK + EU coverage map
Sovereign data residency

UK + EU first. Allied roaming, never opaque.

Every byte and every signalling event is routed through licensed, sovereign points-of-presence under UK or EU jurisdiction. Roaming partners are restricted to allied carriers under bilateral attestation - and the routing decision for every call is signed and exportable.

UK PoP
London + Manchester · UK GDPR · Telecoms Security Act
EU PoP
Frankfurt + Bucharest (Mobifon core) · GDPR · NIS2
Allied roaming
FVEY + EU/EEA only · per-call attestation
Abel evidence pipeline
Continuous evidence pipeline

Sense → Decide → Act → Remember.

Compliance is the by-product of running the platform - not a project we periodically chase. Every layer of Abel writes signed evidence into a SHA-256 hash-chained log; the chain is verifiable by anyone with admin access via the abel_verify_chain RPC.

Sense
Every signalling event, SIM action and admin click is captured at the data plane.
Decide
Three-models classify the event, tag lawful basis, and route by sovereignty.
Act
If warranted: rotate keys, quarantine, kill-switch - sub-60s end to end.
Remember
SHA-256 hash-chained log. Verifiable via abel_verify_chain - any admin, any time.
01

Lawful basis on every record

Every record carries a machine-tagged lawful basis (Art. 6 GDPR) and a purpose-of-processing flag. The basis is enforced at the data plane - not promised in policy.

02

DSAR - 24h SLA

Subject access, rectification and erasure requests are handled by a signed pipeline with a 24-hour SLA. Proof-of-deletion is anchored on the chain.

dpo@boundless.tel
Supply chain & responsible disclosure

No vendor escapes the chain.

Every Tier-1 vendor is attested at provisioning and re-attested on every release. Our responsible-disclosure programme accepts reports 24/7 and commits to a 90-day patch SLA on all confirmed findings.

Mobifon licensed core (UK + EU PoPs) - ISO 27001, ETSI security baseline
Quectel · Fibocom · Rakwireless - GSMA NESAS-aligned modules
Bittium Tough Mobile 2 - NCSA-evaluated, FIPS 140-2
Vuln disclosure: security@boundless.tel · 90-day patch SLA
Boundless 24/7 NOC
Beyond compliance

Safety, accessibility and consumer rights are first-class.

Children & families

Family-pack ships with kid-mode at the SIM. Network-level filtering with parental override; no in-app trickery.

Online Safety Act

Accessibility - WCAG 2.2 AA

Public site and admin console audited against WCAG 2.2 AA. Screen reader-first navigation; reduced-motion respected.

EAA · UK Equality Act

Telecoms consumer rights

Ofcom General Conditions honoured: switching, complaints handling, transparency on speed/coverage. Plain-English contracts.

Ofcom GC
Audit & certification roadmap

Certs are catching up to the platform.

We've architected the platform to exceed the controls these regimes require; we're now paying for the formal stamps.

Q1 2026
ISO 27001:2022 - Stage 1 audit
on track
Q3 2026
ISO 27001:2022 - certification
on track
Q4 2026
PCI-DSS v4.0 - attestation
on track
Q1 2027
SOC 2 Type II - first 12-month report
on track
Q2 2027
GSMA NESAS - vendor product attestation
on track
Evidence pack

One click. Signed. Hash-anchored.

Admins can export a JSON evidence bundle with the chain status, audit row count, latest pentest summary and a signed SHA-256 hash. The export action itself writes a Layer-26 audit row.

Sign in as admin to export

The evidence pack contains live, signed compliance metadata. Available to authenticated administrators only.

Sign in

Bring your hardest auditor.

We'll walk through every control, layer by layer, with our compliance and security leads in the room.

Book a compliance deep-dive