Compliance
What we can evidence today, and what we cannot.
We do not hold ISO 27001, SOC 2 or any other security certification. If your procurement process requires one, that is a real constraint and you should know it now rather than at contract stage.
Available today, and planned
Everything marked available can be produced on request. Everything marked planned is an intention with no date attached to it here.
| Item | Status | Detail |
|---|---|---|
| GDPR compliance | Available today | EU hosting, processor obligations, data subject rights support. |
| Data Processing Agreement | Available today | Signed before processing begins. Your template accepted for review. |
| Public subprocessor list | Available today | Published in this Trust Center with purpose and region. |
| Security questionnaire responses | Available today | Answered by an engineer, not from a template. |
| Architecture review under NDA | Available today | Detailed infrastructure and data flow walkthrough. |
| Breach notification commitment | Available today | Without undue delay, supporting your Article 33 obligation. |
| Independent penetration test | Planned | Not yet commissioned. Customer-commissioned testing accommodated. |
| Automated dependency scanning | Planned | Dependency review is manual today. |
| ISO 27001 certification | Planned | Not held. No audit scheduled. |
| SOC 2 report | Planned | Not held. No audit scheduled. |
| Documented periodic access reviews | Planned | Access is reviewed on change, not on a schedule. |
| Scheduled restore drills | Planned | Restores are verified when performed. |
What procurement usually asks next
Are you ISO 27001 or SOC 2 certified?
No. We hold no security certifications, and there is no audit under way.
Certification is a real signal and we are not going to pretend the absence of one is unimportant. What we offer instead is a published account of the controls that exist, an architecture review with the engineers who built the platform, and answers to your questionnaire that describe the running system rather than a policy document.
If certification is mandatory in your process, we would rather establish that in the first conversation.
Are you GDPR compliant?
We operate under the GDPR as a Swedish company processing data in the EU, and the obligations that fall on us as processor are described concretely on the Privacy page: EU hosting, a signed DPA, support for data subject rights, a public subprocessor list, and breach notification without undue delay.
GDPR compliance is not a certificate anyone issues. It is a set of obligations shared between you as controller and us as processor, and the honest form of this answer is the specifics rather than the label.
Have you been independently audited?
No. The platform has not been subject to an independent security audit or penetration test. This is the single largest gap in this page and we are not going to bury it in a list.
Can we run our own security assessment?
Yes. We will accommodate a customer-commissioned penetration test or security assessment against a staging environment — scope and timing agreed in advance so that a test is not mistaken for an attack.
We will also complete your security questionnaire. Those answers are written by someone who works on the platform, which is why they occasionally say a control is not in place.
Do you carry insurance?
Liability arrangements are part of the commercial agreement rather than something we publish here. Raise it during contract discussion and it will be answered specifically.
What happens if your company ceases to operate?
Your data is exportable at any time in a machine-readable form, and your system runs on standard, widely supported database technology rather than a proprietary store. That is what makes an exit technically possible rather than theoretical.
Escrow and continuity arrangements can be discussed as part of a commercial agreement.
Working through a vendor assessment?
Send us the questionnaire. It comes back answered by an engineer, with the gaps marked as gaps.