Security is the product
We treat your data the way we'd want ours treated — encrypted, audited, and minimally accessed. Everything on this page is verifiable and reviewed quarterly.
Independently audited
SOC 2 Type II
Annual audit by an accredited third-party. Report available under NDA.
ISO 27001
Information security management system certified since 2024.
GDPR
Data processing addendum, EU representative, and DSAR workflow.
HIPAA
Business Associate Agreement on Business and Enterprise plans.
CCPA
California consumer rights honored with 30-day response SLA.
PCI DSS
Payment card data handled exclusively via certified processors.
99.998% over the last 90 days
How we protect your workspace
Encryption everywhere
TLS 1.3 in transit. AES-256 at rest. Per-workspace envelope keys with 90-day rotation.
SSO & SCIM
SAML 2.0 and OIDC with any IdP. Just-in-time provisioning and automated deprovisioning.
Granular RBAC
Predefined and custom roles with field-level scopes and per-view permissions.
Immutable audit log
Every action captured with actor, IP, payload diff. Streamable to your SIEM.
Continuous backups
Point-in-time recovery to any second in the last 35 days. Cross-region replication.
Independent testing
Quarterly pen-tests by NCC Group. Public bug bounty on HackerOne with 24h triage.
Every vendor we trust with your data
| Provider | Purpose | Region |
|---|---|---|
| Amazon Web Services | Primary cloud infrastructure | US, EU, APAC |
| Cloudflare | Edge network + DDoS protection | Global |
| Stripe | Payment processing | US, EU |
| Postmark | Transactional email delivery | US |
| Datadog | Application performance monitoring | US, EU |
| Vanta | Continuous compliance monitoring | US |
We notify workspace admins at least 30 days before adding or replacing a subprocessor.
Responsible disclosure
Found a vulnerability? Email security@digisto.si or submit through our HackerOne program. We triage within 24 hours and pay bounties up to $25,000 for critical issues.
Enterprise-ready reviews
Get SOC 2 reports, pen-test summaries, DPA, security questionnaires, and a live call with our security team.