01 — Security & compliance

Built to be audited, not just trusted

Every control described here is evidenced in the product. If a claim cannot be demonstrated in an audit export, it does not belong on this page.

Uptime, trailing 12 months

99.99%

Median exception resolution

4.2 hrs

Independent audits per year

3

02 — Attestations

Reports available under NDA

SOC 2 Type II

AICPA TSC

Annual, current

Continuous monitoring with an independent audit each year; report available under NDA.

ISO 27001

ISO/IEC 27001:2022

Certified

Information security management system covering all production environments and staff.

ISO 27018

ISO/IEC 27018:2019

Certified

Controls specific to processing personal data in a cloud environment.

GDPR

EU 2016/679

Compliant

Data processing agreement, records of processing and documented sub-processor list.

Penetration testing

CREST accredited

Twice yearly

Independent testing of application and infrastructure, with remediation SLAs.

Business continuity

ISO 22301 aligned

Tested quarterly

Documented recovery objectives with quarterly failover exercises and published results.

03 — Data handling

Residency and isolation

Storage and processing are pinned per entity. Sovereign deployments run in a named jurisdiction with documented egress controls and no cross-region replication.

Regions

Ireland, Frankfurt, Virginia, Singapore, Sydney

Encryption

AES-256 at rest, TLS 1.3 in transit, customer-managed keys available

Retention

Policy-driven per entity, minimum seven years for governed records

Backups

Hourly incremental, daily full, quarterly restore tests

04 — Sub-processors

Provider

Purpose

Region

Amazon Web Services

Primary hosting and encrypted storage

Per entity

Per entity

Cloudflare

Edge delivery and DDoS protection

Global

Global

Postmark

Transactional notification delivery

EU / US

EU / US

Datadog

Infrastructure observability, no customer records

EU

EU

Vanta

Continuous control monitoring

US

US

Request the full security package

SOC 2 report, penetration test summary, sub-processor list and data processing agreement, sent under NDA.

Typical response within one business day.

Request the full security package

SOC 2 report, penetration test summary, sub-processor list and data processing agreement, sent under NDA.

Typical response within one business day.

Request the full security package

SOC 2 report, penetration test summary, sub-processor list and data processing agreement, sent under NDA.

Typical response within one business day.

Create a free website with Framer, the website builder loved by startups, designers and agencies.