Trust Center

Security you can check, not just read about

Live platform status, an honest account of where we stand on ISO 27001 and SOC 2, and the full picture of where your data lives and who touches it. Nothing on this page is a claim we cannot evidence.

Section 1 — Live transparency

Platform status

Read live from our platform health checks every time this page loads, and refreshed once a minute while it stays open.

Status unavailable

We cannot reach our health checks right now

Last checked 15:22 UTC

Last 90 days

99.44%

90 days agoToday

Current status above is measured live. The 90-day history and the availability figure are illustrative while our metrics feed is being connected — they are not yet measured data.

Incident record

Confirmed security incidents affecting customer data, since we started operating.

Security incidents
0

Confirmed incidents affecting customer data, all time.

Days since last incident
None recorded

Counted from the most recent confirmed incident.

Mean time to resolve
None recorded

Averaged across resolved incidents. Nothing to average yet.

Availability target
99.90%

Contractual monthly availability target for the platform.

Section 2

Compliance & audit posture

Where we actually stand on each framework — including the ones we have not certified against yet.

Frameworks

Where we stand

Each framework carries the status we can actually evidence today. Alignment means we implement the requirements; certification means an auditor has issued a certificate. We do not blur the two.

  • GDPR

    Data processing agreements, EU-only hosting, documented retention and deletion, and a published privacy policy.

    Aligned

  • NIS2

    Risk management, incident handling and supply-chain security practices aligned to the directive's requirements.

    Aligned

  • ISO 27001

    Our ISMS and Annex A controls are being implemented against the standard. We are not certified yet.

    In progress

    Target: certification audit in H2 2026

  • SOC 2

    Planned after ISO 27001. No audit has been scoped and no report exists today.

    Planned

    Target: scoping starts after ISO 27001 certification

SypraSam is not currently ISO 27001 certified and holds no SOC 2 attestation. We publish the status of every framework — including the ones still in progress — rather than a wall of badges, because you will find out either way during due diligence.

Certification roadmap

The ISO 27001 path and the phase we are in right now.

  1. Gap assessment

    Measured our existing controls against Annex A and recorded what was missing.

  2. Controls implementation

    Closing the gaps and building the evidence trail an auditor will ask for.

    We are here

  3. Stage 1 audit

    External review of our ISMS documentation and readiness.

  4. Stage 2 audit

    External review of the controls operating in practice.

  5. Certification

    Certificate issued. Until then, this page will not show one.

Control matrix

The controls we operate, grouped the way ISO 27001:2022 Annex A groups them. This is the same inventory we take into the audit.

Organizational

Annex A.5

  • Penetration testing

    Independent testing of the platform, with findings tracked to closure.

  • Supplier management

    Every subprocessor is assessed and under a data processing agreement before it touches production.

  • Incident response

    A defined process for detecting, triaging, communicating and closing security incidents.

  • Access lifecycle

    Access is granted on need-to-know when someone joins a role and revoked when they leave it.

People

Annex A.6

  • Confidentiality obligations

    Everyone with access to customer data is bound by written confidentiality obligations.

Physical

Annex A.7

  • EU data centres

    Physical security is provided by Hetzner's certified data centres in Germany.

Technological

Annex A.8

  • Encryption in transit

    All traffic to and inside the platform is TLS-encrypted.

  • Encryption at rest

    Databases, backups and object storage are encrypted at rest.

  • Role-based access control

    Permissions are granted by role, with least privilege as the default.

  • Tenant isolation

    Each customer runs behind its own namespace, node pool and database boundary.

  • Audit logging

    Security-relevant actions are logged with actor, time and object.

  • High availability & backups

    Redundant components plus regular, restorable backups of all customer data.

  • Vulnerability management

    Dependencies and images are scanned, and findings are prioritised by severity.

  • Secrets management

    Credentials live in a managed secret store, never in code or configuration files.

Section 3

Data & architecture transparency

Where your data is hosted, who processes it, how tenants are separated and when it is deleted.

Data residency

All data hosted and processed in the EU

The platform runs in Hetzner data centres in Germany. Customer data is stored and processed inside the European Union; the only processing that can leave the EU is AI-assisted extraction, and it is listed openly below.

Hosting
Hetzner, Germany
Processing
European Union
Third-country transfers
AI processors only, under SCCs

Subprocessors

Every third party that can process data on our behalf, what it is used for, and the safeguard that covers it.

Subprocessors
SubprocessorPurposeProcessing locationTransfer safeguard
Hetzner Online GmbH PlatformInfrastructure and data centre hosting for the platform.Germany (EU)Stays in the EU
Google Ireland Limited This websiteWebsite analytics after consent.Ireland (EU) and United StatesStandard Contractual Clauses

A data processing agreement is in place with every subprocessor listed here. We will notify customers before adding a new subprocessor that processes platform data.

Tenant isolation

How one customer's data is kept away from another's. Shown at the level of the model — the specific topology stays private.

Isolation boundaries, outermost first

Your tenant

Dedicated namespace

Dedicated node pool

Separate database

Separate credentials

Another tenant

Separated by the same four boundaries. No shared namespace, node pool, database or credentials.

Dedicated namespace
Workloads run in a namespace of their own, with network policy restricting what may talk to them.
Dedicated node pool
Compute is not shared with other tenants, so noisy neighbours and cross-tenant escape are both off the table.
Separate database
Each tenant has its own database rather than a shared schema with a tenant column.
Separate credentials
Every tenant's services authenticate with their own credentials, scoped to that tenant alone.

Data flow & retention

What we collect, where it goes, how long it stays and what ends it.

  1. Step 1

    Collect

    Data arrives from your connectors, uploads and user activity.

  2. Step 2

    In transit

    Every hop is TLS-encrypted, inbound and inside the platform.

  3. Step 3

    Process

    Normalisation, matching and AI-assisted extraction produce your inventory.

  4. Step 4

    Store

    Encrypted at rest in your own database in the EU, with restorable backups.

  5. Step 5

    Delete

    Removed on your request or on contract end, backups included.

Retention and deletion by data category
Data categoryPurposeRetentionDeletion
Identity dataNames, work email addresses and roles used to attribute licences to people.For the contract termWithin 30 days of contract end or on request
Software & licence dataInstalled software, entitlements, contracts and spend — the inventory itself.For the contract termWithin 30 days of contract end
Usage telemetryWhich applications are actually used, to find unused licences.24 months rollingAutomatically once out of the window
Audit logsSecurity-relevant actions, for your audits and ours.12 monthsAutomatically once out of the window
Support correspondenceTickets and messages exchanged with our team.24 months after closureAutomatically, or on request

On termination, customer data is deleted within 30 days unless a longer statutory retention period applies. Export before deletion is available on request.

Section 4

Proof & engagement

The documents behind the claims, how to report a vulnerability, and what we have shipped recently.

Security package

Request our security pack

One bundle that answers most of a security questionnaire before you have to send one.

  • Security whitepaper — architecture, controls and operational practices in detail.
  • Data processing agreement — our standard DPA including the subprocessor list.
  • SIG / CAIQ responses — the standard questionnaires, pre-filled.
  • Penetration test summary — scope, findings by severity and remediation status.
Request the security pack

Sent by email, usually within two business days. We ask for a company address so we know who received which version.

Report a vulnerability

Found something? Tell us before you tell anyone else and we will work it with you. Good-faith research is welcome here.

  • We acknowledge every report within two business days.
  • We will not pursue legal action against good-faith research that follows this policy.
  • We credit reporters who want to be named once the issue is fixed.
  • In scope: our platform and this website. Out of scope: denial of service, social engineering and physical attacks.
Security contact
info@syprasam.org
Machine-readable policy
/.well-known/security.txt

Security changelog

Security-relevant changes we have shipped, newest first.

  1. Consent Mode v2, denied by default

    Privacy

    Analytics signals are denied until a visitor opts in, and no analytics script loads before consent.

  2. Non-production deployments excluded from search

    Hardening

    Staging and preview environments now serve noindex and disallow crawling, so pre-release content cannot be indexed.

  3. Contact endpoint hardened

    Hardening

    Server-side schema validation, per-IP rate limiting and a honeypot field on the public contact form.

Entries are published once the change is live. Automated scan results are labelled as such so you can tell a machine finding from a human claim.