Trust centre
What we do with your data, in plain language.
Everything below is either already in our legal terms or something you could check in the product today. The last section lists what we do not have yet, because that is the part most trust pages leave out.
EUWhere your data is stored
DPASigned as your processor
3Sub-processors, all listed
0Advertising cookies
Controls
How the platform is protected.
Accounts and access
The things that stop somebody signing in as one of your people.
- Passwords are hashed, never storedWe cannot read your password. A reset issues a new one-time link rather than mailing the old one.
- Two-step sign-in with recovery codesTime-based codes from any authenticator app. Ten one-shot recovery codes so a lost phone is not a lost account.
- Lockout after repeated failuresEight wrong attempts locks the account for fifteen minutes. A wrong two-step code counts the same as a wrong password.
- Every sign-in is recordedYou can see the last sixty attempts on your own account, successful or not, with device and address.
- Sessions you can end yourselfEvery signed-in device is listed by browser and address. Sign out one, or all the others, without asking us.
Your data
Where it sits and who can reach it.
- Stored in the EUApplication hosting and data storage stay within the EU, as set out in our DPA.
- You are the controller, we are the processorWe process personal data only on your documented instructions, and delete or return it when the agreement ends.
- Session tokens are hashed at restA copy of our session table would not let anyone sign in as you.
- Requests are origin-checkedThe API refuses calls that did not come from our own pages, so another site cannot act on your behalf.
- Card numbers never reach usStripe takes the payment. We store a reference, never a card number.
Sub-processors
Everyone who touches your data.
The complete list. If it changes, this page changes.
| Who | What for | Where |
|---|---|---|
| Stripe | Card payments and invoicing | EU / global |
| Our EU hosting provider | Application hosting and data storage | EU |
Honest gaps
What we do not have yet.
A trust page that lists only good news is not a trust page. These are the questions a careful buyer asks, answered the way we would answer them on a call.
No ISO 27001 or SOC 2 certification
We have not been audited against either standard. The controls above are real and you
can verify them in the product, but nobody independent has signed off on them. If your
procurement process requires a certificate, we are not there yet — and we would rather you
knew now than after a trial.
No third-party penetration test published
No external test report exists to share. Say so in a security review rather than
assuming one is on file.
No contractual uptime SLA on standard plans
We do not promise a percentage we have not measured for long enough to stand behind.
Larger agreements can include one — ask us.
Something not answered here?
Security questionnaires, a copy of the DPA, or a specific question about how something works — a person replies, usually the same day.
Ask us Read the DPA