The basics
Where your data sits, and who can touch it.
- Data residency
- Configurable per engagement; EU/US regions available.
- Encryption
- In transit (TLS 1.2+) and at rest (AES-256).
- Access control
- Read-only during Discovery; least-privilege, scoped, time-bound thereafter. SSO/MFA on all internal access.
- Sub-processors
- Disclosed list, maintained and versioned. Notice before changes.
- Incident response
- Documented runbook; breach notification within GDPR timelines.
- GDPR role
- Processor. We act on your documented instructions.
Standards
Certifications & roadmap
| Standard | Status |
|---|---|
| GDPR processor posture | Live |
| SOC 2 Type II | In progress(target Q4 2026) |
| ISO 27001 | Roadmap |
We don’t claim certifications we don’t hold. What you see is current.
For your review
Documents
- DPA templatePDFDownload ↓
- Security overviewPDFDownload ↓
- Sub-processor listPDFDownload ↓
- SOC 2 reportOn requestRequest
