Trust center

Documents, attestations, and reports โ€” all in one place.

๐Ÿ“‹ SOC 2 Type II report

Annual third-party audit covering security, availability, confidentiality.

85% complete
Request under NDA

๐Ÿ“‹ ISO 27001 certificate

Information security management system certification.

Oct 2026 target
Notify when ready

๐Ÿ“‹ Penetration test report

Latest by CrowdSec ยท April 2026 ยท 0 critical findings.

Available
Request under NDA

๐Ÿ“‹ HIPAA BAA template

Standard business associate agreement for US healthcare.

Available
Download template

๐Ÿ“‹ Data Processing Addendum

GDPR-compliant DPA ยท UK GDPR ยท DPDP-aligned.

Available
View DPA

๐Ÿ“‹ SCC (EU model clauses)

Standard contractual clauses for EU-to-third-country transfers.

Available
Download

๐Ÿ“‹ Subprocessor list

Live list of all subprocessors with their roles and locations.

Public
View list

๐Ÿ“‹ Privacy policy

How we collect, use, and protect personal data globally.

Available
View policy

๐Ÿ“‹ CAIQ / SIG Lite

Cloud Security Alliance + Shared Assessments questionnaires.

Pre-filled
Request

๐Ÿ“‹ Insurance certificates

Cyber liability ($10M), E&O ($5M), General liability.

Available
Request COI

๐Ÿ“‹ Service Level Agreement

Uptime, response time, and credit policies per plan.

Available
View SLA

๐Ÿ“‹ Vendor security questionnaire

Our standard intake form for evaluating subprocessors.

Internal
Request

Subprocessors

We use these vetted vendors. Each one signs a DPA mirroring or stricter than the one we sign with you.

VendorPurposeRegionTier
Amazon Web ServicesPrimary cloud ยท compute, DB, storageMulti-regionCritical
CloudflareCDN, WAF, DNS, DDoS protectionGlobalCritical
StripePayment processing (US, EU, UK, AU)US/EU/SGCritical
RazorpayPayment processing (India)IndiaCritical
TwilioSMS + voice (global)US/EUHigh
MSG91SMS (India)IndiaHigh
Meta WhatsApp BusinessWhatsApp messagingGlobalHigh
ResendTransactional emailUS/EUHigh
SendGridTransactional email (failover)USMedium
OpenAILLM (opt-in only)USMedium
AnthropicLLM (opt-in only)USMedium
DatadogObservability (no PII)US/EUMedium
HackerOneVulnerability disclosureUSLow