Compliance
Compliance Status
Last updated: 8 July 2026. We'd rather tell you exactly what we have and don't have today than make vague promises — this page is kept current as our posture changes.
GDPR
We process personal data in line with the GDPR: a published Data Processing Agreement (Article 28), a Privacy Policy describing what we collect and why, self-service data export and account deletion from the Account page, and a documented sub-processor list with transfer safeguards for the few processors outside the EEA.
SOC 2
We are not SOC 2 Type II certified. That audit is a meaningful commitment of time and cost we haven't undertaken yet at our current size. What we do have today, covering the same control areas a SOC 2 audit would examine:
- Encryption in transit (TLS 1.2+) and at rest; API keys and webhook secrets stored as salted hashes, never plaintext.
- Role-based access control (admin/engineer/viewer) on every organization, enforced server-side on every request.
- An immutable audit log of security-relevant account actions, queryable by admins at /audit-logs.
- Automated dependency and secret scanning on every code change.
- Per-organization and per-IP rate limiting, SSRF-safe webhook URL validation, and request-size limits.
- Self-tracked uptime monitoring with public history at /sla, and critical-alert paging on infrastructure failures.
- Daily database backups with point-in-time recovery.
Formal SOC 2 certification is on our roadmap as we grow. If it's a hard requirement for your procurement process today, tell us — it affects how we prioritize it.
ISO 27001
We do not hold ISO 27001 certification and have not begun a formal ISMS (Information Security Management System) audit process. Many of the underlying controls ISO 27001 expects overlap with what's listed under SOC 2 above, but we make no certification claim.
Data Residency
Primary application and database infrastructure runs in the EEA. A small number of sub-processors (identity/auth, payments, transactional email, error tracking) are US-based companies operating under Standard Contractual Clauses or the EU-US Data Privacy Framework — the full list is published in the DPA's sub-processor annex. We do not currently offer a contractual EU-data-residency-only guarantee (i.e., a commitment that no sub-processor ever touches data outside the EEA) — ask if that's a hard requirement.
Other things people ask about
- Two-factor authentication: supported for account sign-in — see Security.
- SSO / SAML: available for Enterprise customers via our identity provider — see Security or contact us to set up a connection.
- Responsible disclosure: we have a published vulnerability-reporting policy — see Security Disclosure Policy.
- Penetration testing: conducted internally; we have not yet commissioned an independent third-party penetration test.
- Cyber insurance: not yet in place.
Questions about any of this, or need something specific for a procurement review? Email security@orbitalert.net. See also Security, DPA, and Privacy Policy.