Sound's like your hosted version will end up with a lot of potentially sensitive information. You will probably want to add ISO 27001 and / or SOC 2 Type 2 as a priority. Not to say an org with that is more secure than one without, but you will certainly need to evidence a comprehensive security program to pass procurement. Choosing what third parties you add now (libraries, platforms etc) can save you a TON down the road.
Yes you're right. SOC 2 is our priority for the next few weeks.
If you have experience in enterprise sales, I'd love to chat (nael@panora.dev). Thanks.