Skip to content

合规性

Cap 以隐私优先、自托管为设计理念,这让大多数合规问题都变得简单:**你的用户数据永远不会离开你的基础设施。**对终端用户没有 Cookie 或跟踪,验证流程中没有第三方调用,工作量证明(PoW)完全在访客的浏览器中运行。

Privacy & data protection

  • GDPREuropean Union

    General Data Protection Regulation

    No cookies or tracking for end users and no third-party calls. You stay the sole controller.

  • CCPA / CPRACalifornia, USA

    California Consumer Privacy Act

    Cap never sells or shares personal information and builds no consumer profiles.

  • HIPAAUnited States

    Health Insurance Portability and Accountability Act

    No PHI is ever touched and everything runs on your own infrastructure.

  • PIPEDA / CPPACanada

    Personal Information Protection and Electronic Documents Act

    No personal information is collected, disclosed, or sold to third parties.

  • LGPDBrazil

    Lei Geral de Proteção de Dados

    Self-hosted with no profiling and no data sharing keeps processing minimal and fully under your control.

  • DPDPAIndia

    Digital Personal Data Protection Act

    No personal data is stored or shared, and nothing leaves your servers.

  • PIPLChina

    Personal Information Protection Law

    Self-host in-region and no data ever leaves your infrastructure.

  • 152-FZRussia

    Federal Law No. 152-FZ "On Personal Data"

    Self-host on your own infrastructure, including in-region. No cookies, tracking, profiling, or third-party calls are required in the verification flow.

Accessibility

  • WCAG 2.2 AAInternational

    Web Content Accessibility Guidelines

  • EAA / EN 301 549European Union

    European Accessibility Act

  • Section 508United States

    Rehabilitation Act, Section 508

  • i18nGlobal

    Localization & RTL support

This page describes how Cap is designed to support these regulations. It is not legal advice. Your overall compliance also depends on how you deploy Cap and the rest of your application.