A factual reference for security teams. Every control listed here maps to live code or operational practice — not aspirations.
Last updated: August 13, 2026
We're transparent about where we are. The matrix below distinguishes what's in place today from what's on the roadmap. If a buyer requires a formal report we don't yet have, talk to us — we may pursue it sooner.
| Standard | Status | Notes |
|---|---|---|
| GDPR | In place | 4-category cookie consent, DSAR support, EU-only data residency, DPA available on request. |
| PCI DSS | In place | Inherited — payment data handled exclusively by Stripe Checkout. We never see card numbers. |
| SOC 2 Type II | Not yet | Not currently certified. We can share our control summary and complete security questionnaires (SIG Lite, CAIQ-Lite) on request. |
| ISO 27001 | Not yet | Not currently certified. Many of the underlying controls are already in place; formal certification on roadmap when buyers require it. |
| External penetration test | Not yet | Annual third-party pen test on the roadmap. We respond to coordinated disclosure today (see incident response). |
Customer data is hosted on Contabo infrastructure located in France, within the EU. We do not replicate customer databases outside the EU. Subprocessor data flows are listed below.
TLS 1.2 or higher in transit. Backups are encrypted client-side with AES-256 before they leave the host, and the encryption key never reaches the storage provider. Secrets are managed via environment variables on the host, never committed to source control.
Customer data is retained for the lifetime of your account. Deletion requests under GDPR are honored within 30 days. Backup snapshots follow a 7 daily / 4 weekly / 6 monthly rotation, so a snapshot may persist for up to six months before it is pruned.
Automated daily backups of the production database, encrypted client-side and shipped to EU-jurisdiction offsite storage, with random integrity verification on every run. Restores are not assumed to work: a scripted restore test runs on a schedule against a real snapshot, and a missed or failed backup run raises an alert rather than passing silently.
You can access, export, correct, or delete your data at any time. See our Privacy Policy for the full list of rights and how to exercise them.
Third parties we share specific data with to operate the service. Each is bound by a Data Processing Agreement.
| Vendor | Purpose | Data shared | Region |
|---|---|---|---|
| Stripe | Payments, billing, tax | Billing email, name, payment method (handled entirely by Stripe — we never see PAN) | US / EU |
| Amazon Web Services (SES) | Transactional email | Recipient email and message content (verification, invitations, notifications); delivery, bounce and complaint events | EU (Frankfurt) |
| Daily.co | Live interview video | Display name, interview room ID; ephemeral A/V streams during the call | EU / US |
| Cloudflare | CDN, WAF, Turnstile bot protection, encrypted offsite backup storage (R2) | IP address, request metadata, Turnstile challenge tokens; encrypted backup archives we hold the only key to | Global edge; backups EU jurisdiction |
| Contabo | Compute, database, Redis hosting | All customer data at rest | EU (France) |
| Sentry | Application error monitoring | Exception stack traces and request metadata; may include user and company identifiers | EU (Germany) |
| Grafana Cloud | Infrastructure metrics and log aggregation | Service metrics and container logs, which may contain IP addresses and request metadata | EU |
We notify customers of material subprocessor changes via email at least 30 days before they take effect.
Found a vulnerability? Email us. We acknowledge reports within 24 hours and will not pursue legal action against researchers acting in good faith.
Include reproduction steps. PGP key available on request.
Acknowledge
Within 24 hours
Initial assessment
Within 5 business days
Customer notification
Without undue delay if their data is affected (GDPR Art. 33–34 timelines)
We'll complete your security questionnaire (SIG Lite, CAIQ-Lite, or your own template), share our DPA, and walk your security team through any control in detail.
Available on request: DPA, subprocessor list, GDPR data flow diagram, architecture overview.