Trust Center

Compliance

What we can evidence today, and what we cannot.

We do not hold ISO 27001, SOC 2 or any other security certification. If your procurement process requires one, that is a real constraint and you should know it now rather than at contract stage.

Status

Available today, and planned

Everything marked available can be produced on request. Everything marked planned is an intention with no date attached to it here.

Planned means intended and not yet in place. It does not mean in progress, and no date is implied by its presence in this table.
ItemStatusDetail
GDPR complianceAvailable todayEU hosting, processor obligations, data subject rights support.
Data Processing AgreementAvailable todaySigned before processing begins. Your template accepted for review.
Public subprocessor listAvailable todayPublished in this Trust Center with purpose and region.
Security questionnaire responsesAvailable todayAnswered by an engineer, not from a template.
Architecture review under NDAAvailable todayDetailed infrastructure and data flow walkthrough.
Breach notification commitmentAvailable todayWithout undue delay, supporting your Article 33 obligation.
Independent penetration testPlannedNot yet commissioned. Customer-commissioned testing accommodated.
Automated dependency scanningPlannedDependency review is manual today.
ISO 27001 certificationPlannedNot held. No audit scheduled.
SOC 2 reportPlannedNot held. No audit scheduled.
Documented periodic access reviewsPlannedAccess is reviewed on change, not on a schedule.
Scheduled restore drillsPlannedRestores are verified when performed.
Questions

What procurement usually asks next

Are you ISO 27001 or SOC 2 certified?

No. We hold no security certifications, and there is no audit under way.

Certification is a real signal and we are not going to pretend the absence of one is unimportant. What we offer instead is a published account of the controls that exist, an architecture review with the engineers who built the platform, and answers to your questionnaire that describe the running system rather than a policy document.

If certification is mandatory in your process, we would rather establish that in the first conversation.

Are you GDPR compliant?

We operate under the GDPR as a Swedish company processing data in the EU, and the obligations that fall on us as processor are described concretely on the Privacy page: EU hosting, a signed DPA, support for data subject rights, a public subprocessor list, and breach notification without undue delay.

GDPR compliance is not a certificate anyone issues. It is a set of obligations shared between you as controller and us as processor, and the honest form of this answer is the specifics rather than the label.

Have you been independently audited?

No. The platform has not been subject to an independent security audit or penetration test. This is the single largest gap in this page and we are not going to bury it in a list.

Can we run our own security assessment?

Yes. We will accommodate a customer-commissioned penetration test or security assessment against a staging environment — scope and timing agreed in advance so that a test is not mistaken for an attack.

We will also complete your security questionnaire. Those answers are written by someone who works on the platform, which is why they occasionally say a control is not in place.

Do you carry insurance?

Liability arrangements are part of the commercial agreement rather than something we publish here. Raise it during contract discussion and it will be answered specifically.

What happens if your company ceases to operate?

Your data is exportable at any time in a machine-readable form, and your system runs on standard, widely supported database technology rather than a proprietary store. That is what makes an exit technically possible rather than theoretical.

Escrow and continuity arrangements can be discussed as part of a commercial agreement.

Working through a vendor assessment?

Send us the questionnaire. It comes back answered by an engineer, with the gaps marked as gaps.