All systems operational

Security is the product

We treat your data the way we'd want ours treated — encrypted, audited, and minimally accessed. Everything on this page is verifiable and reviewed quarterly.

SOC 2 Type IIISO 27001HIPAAGDPRCCPA
Compliance

Independently audited

Certified

SOC 2 Type II

Annual audit by an accredited third-party. Report available under NDA.

Certified

ISO 27001

Information security management system certified since 2024.

Compliant

GDPR

Data processing addendum, EU representative, and DSAR workflow.

BAA available

HIPAA

Business Associate Agreement on Business and Enterprise plans.

Compliant

CCPA

California consumer rights honored with 30-day response SLA.

SAQ-A

PCI DSS

Payment card data handled exclusively via certified processors.

Reliability

99.998% over the last 90 days

90 days ago99.998%today
US East
62ms
US West
71ms
EU Frankfurt
84ms
EU Dublin
78ms
AP Singapore
96ms
AP Tokyo
102ms
Practices

How we protect your workspace

Encryption everywhere

TLS 1.3 in transit. AES-256 at rest. Per-workspace envelope keys with 90-day rotation.

SSO & SCIM

SAML 2.0 and OIDC with any IdP. Just-in-time provisioning and automated deprovisioning.

Granular RBAC

Predefined and custom roles with field-level scopes and per-view permissions.

Immutable audit log

Every action captured with actor, IP, payload diff. Streamable to your SIEM.

Continuous backups

Point-in-time recovery to any second in the last 35 days. Cross-region replication.

Independent testing

Quarterly pen-tests by NCC Group. Public bug bounty on HackerOne with 24h triage.

Subprocessors

Every vendor we trust with your data

ProviderPurposeRegion
Amazon Web ServicesPrimary cloud infrastructureUS, EU, APAC
CloudflareEdge network + DDoS protectionGlobal
StripePayment processingUS, EU
PostmarkTransactional email deliveryUS
DatadogApplication performance monitoringUS, EU
VantaContinuous compliance monitoringUS

We notify workspace admins at least 30 days before adding or replacing a subprocessor.

Responsible disclosure

Found a vulnerability? Email security@digisto.si or submit through our HackerOne program. We triage within 24 hours and pay bounties up to $25,000 for critical issues.

Enterprise-ready reviews

Get SOC 2 reports, pen-test summaries, DPA, security questionnaires, and a live call with our security team.