OrbitAlert
Sign in →

Compliance

Compliance Status

Last updated: 8 July 2026. We'd rather tell you exactly what we have and don't have today than make vague promises — this page is kept current as our posture changes.

GDPR

In placeCompliant

We process personal data in line with the GDPR: a published Data Processing Agreement (Article 28), a Privacy Policy describing what we collect and why, self-service data export and account deletion from the Account page, and a documented sub-processor list with transfer safeguards for the few processors outside the EEA.

SOC 2

PartialNot certified — SOC 2-aligned practices

We are not SOC 2 Type II certified. That audit is a meaningful commitment of time and cost we haven't undertaken yet at our current size. What we do have today, covering the same control areas a SOC 2 audit would examine:

  • Encryption in transit (TLS 1.2+) and at rest; API keys and webhook secrets stored as salted hashes, never plaintext.
  • Role-based access control (admin/engineer/viewer) on every organization, enforced server-side on every request.
  • An immutable audit log of security-relevant account actions, queryable by admins at /audit-logs.
  • Automated dependency and secret scanning on every code change.
  • Per-organization and per-IP rate limiting, SSRF-safe webhook URL validation, and request-size limits.
  • Self-tracked uptime monitoring with public history at /sla, and critical-alert paging on infrastructure failures.
  • Daily database backups with point-in-time recovery.

Formal SOC 2 certification is on our roadmap as we grow. If it's a hard requirement for your procurement process today, tell us — it affects how we prioritize it.

ISO 27001

Not yet — roadmapNot certified

We do not hold ISO 27001 certification and have not begun a formal ISMS (Information Security Management System) audit process. Many of the underlying controls ISO 27001 expects overlap with what's listed under SOC 2 above, but we make no certification claim.

Data Residency

In placeEU-primary

Primary application and database infrastructure runs in the EEA. A small number of sub-processors (identity/auth, payments, transactional email, error tracking) are US-based companies operating under Standard Contractual Clauses or the EU-US Data Privacy Framework — the full list is published in the DPA's sub-processor annex. We do not currently offer a contractual EU-data-residency-only guarantee (i.e., a commitment that no sub-processor ever touches data outside the EEA) — ask if that's a hard requirement.

Other things people ask about

  • Two-factor authentication: supported for account sign-in — see Security.
  • SSO / SAML: available for Enterprise customers via our identity provider — see Security or contact us to set up a connection.
  • Responsible disclosure: we have a published vulnerability-reporting policy — see Security Disclosure Policy.
  • Penetration testing: conducted internally; we have not yet commissioned an independent third-party penetration test.
  • Cyber insurance: not yet in place.

Questions about any of this, or need something specific for a procurement review? Email security@orbitalert.net. See also Security, DPA, and Privacy Policy.