Certifications & Attestations
Independently examined and third-party verified
Hover any badge for the issuing body, the scope of the assessment and its current status.

ISAE 3402 Type II
Audit Completed
ISAE 3402 Type II
International Auditing and Assurance Standards Board
Third-party assurance report for service organizations, covering the design and operating effectiveness of controls over the reporting period.
Audit Completed
PCI Security Standards Council
Participating Organization
PCI Security Standards Council
PCI Security Standards Council
Participating Organization. Cardholder data for POS and subscription payments is processed by our PCI DSS Level 1 payment processors; card numbers never transit or rest in platform storage.
Participating Organization
GDPR
Compliant
GDPR
European Union — Regulation 2016/679
Data protection and sovereignty commitments covering lawful basis, data subject rights, breach notification and processor obligations.
Compliant
BSI ISO/IEC 27001
Certified
BSI ISO/IEC 27001
BSI (British Standards Institution)
Information Security Management System certified against ISO/IEC 27001, covering risk treatment, access control, cryptography and supplier security.
Certified
ANAB Accredited
Accredited
ANAB Accredited
ANSI National Accreditation Board
Certification issued by a management systems certification body accredited to ISO/IEC 17021-1, establishing the competence of the certifying auditor.
Accredited
IAF MLA
Recognized
IAF MLA
International Accreditation Forum
Member of the IAF Multilateral Recognition Arrangement, under which the certification is recognized across participating accreditation bodies worldwide.
RecognizedSecurity Controls
How the platform is protected
Control families mapped to their Trust Services Criteria references.
Logical Access
CC6.1Identity, authorization and tenant isolation.
- Single sign-on with OIDC identity federation
- Role-based access control with per-action grant matrices
- Row-Level Security enforced at the database layer, per tenant
- Least-privilege service roles for server-side operations
Threat Prevention
CC6.8Preventing unauthorized or malicious software and access.
- Encryption in transit (TLS) and at rest
- Secrets held in a managed secret store, never in source control
- Signed and secret-verified inbound webhooks
- Managed endpoint detection and patch compliance monitoring
System Monitoring
CC7.2Detecting and acting on anomalies.
- Immutable audit ledger for privileged and financial operations
- Fail-closed audit records written before any mutation
- Authentication event logging
- Alert triage with severity-based escalation and SLA tracking
Change Management
CC8.1Authorizing, testing and recording changes.
- Versioned release manifest with a published change log
- Reviewed changes with documented rollback paths
- Segregated configuration per environment
- Two-person approval for destructive remote actions
Document Vault
Assurance documentation on request
These documents are released under a confidentiality agreement and delivered by our security team.
SOC 2 Type II Report
Full attestation report covering the Trust Services Criteria over the examination period.
Penetration Test Summary
Executive summary of the most recent third-party penetration test, including remediation status.
Disaster Recovery Plan
Business continuity and disaster recovery procedures, including recovery objectives.
ISO/IEC 27001 Certificate
Current certificate of registration and its statement of applicability scope.
Privacy
Subprocessors and data residency
Subprocessors
Third parties that process data on our behalf, and the primary region each operates in.
| Vendor | Service | Primary Region |
|---|---|---|
| AWS | Application hosting, managed database and file storage | United States |
| Cloudflare | Edge delivery, object storage (R2) and transactional email transport | Global edge network |
| Google Cloud / Google Workspace APIs | Calendar, Drive and Gmail integrations, Maps geocoding | Global |
| Stripe | Card and ACH payment processing, subscription billing, payouts | United States |
| Plaid | Bank account linking and transaction synchronization | United States |
| Resend | Sending-domain DKIM and SPF verification | United States |
| Apollo | Sales prospect enrichment for the outbound module | United States |
| OpenRouteService | Commercial vehicle routing and distance calculation | European Union |
| MeshCentral | Remote monitoring and management sessions for managed endpoints | Self-hosted by operator |