01 — Security & compliance
Built to be audited, not just trusted
Every control described here is evidenced in the product. If a claim cannot be demonstrated in an audit export, it does not belong on this page.
Uptime, trailing 12 months
99.99%
Median exception resolution
4.2 hrs
Independent audits per year
3
02 — Attestations
Reports available under NDA
SOC 2 Type II
AICPA TSC
Annual, current
Continuous monitoring with an independent audit each year; report available under NDA.
ISO 27001
ISO/IEC 27001:2022
Certified
Information security management system covering all production environments and staff.
ISO 27018
ISO/IEC 27018:2019
Certified
Controls specific to processing personal data in a cloud environment.
GDPR
EU 2016/679
Compliant
Data processing agreement, records of processing and documented sub-processor list.
Penetration testing
CREST accredited
Twice yearly
Independent testing of application and infrastructure, with remediation SLAs.
Business continuity
ISO 22301 aligned
Tested quarterly
Documented recovery objectives with quarterly failover exercises and published results.
03 — Data handling
Residency and isolation
Storage and processing are pinned per entity. Sovereign deployments run in a named jurisdiction with documented egress controls and no cross-region replication.
Regions
Ireland, Frankfurt, Virginia, Singapore, Sydney
Encryption
AES-256 at rest, TLS 1.3 in transit, customer-managed keys available
Retention
Policy-driven per entity, minimum seven years for governed records
Backups
Hourly incremental, daily full, quarterly restore tests
04 — Sub-processors
Amazon Web Services
Primary hosting and encrypted storage
Cloudflare
Edge delivery and DDoS protection
Postmark
Transactional notification delivery
Datadog
Infrastructure observability, no customer records
Vanta
Continuous control monitoring