Auditor
What we do to meet the EU and US frameworks that matter to our customers. Language of commitments, not of claims: we describe practices, we do not assert conformity.
Last reviewed on 2026-09-19.
How we process personal data as a processor for our customers and as a controller for account data.
Where execution and evidence live for organisations that declare the EU as their data region.
Transparency obligations as a deployer of AI systems used in AI-assisted checks.
What we provide to customers with their own NIS2 or DORA obligations.
Cookies and tracking on the public site.
Rights of California residents over their personal information.
Controls aligned with the SOC 2 trust services criteria. We are not SOC 2 attested.
The Payments suites run checks aligned with PCI DSS requirements. We are not a PCI DSS assessor and issue no PCI certification.
This page describes our practices. It is not legal advice, not an audit report and not a statement of conformity with any framework.