Security
Practical controls so your compliance workspace stays private, EU-hosted, and reliable — written for agency security and procurement questionnaires.
For questionnaires
A short ZIP with our security overview, DPA summary, and sub-processors snapshot — for client or internal security questionnaires.
Informational only. Not a signed agreement, certificate, or audit attestation. Prefer the live pages on this site for the latest wording.
Primary workspace data — database records and evidence files — is stored in the European Union. We choose infrastructure and providers with data processing agreements appropriate to that processing, so your agency’s compliance records stay in European jurisdiction for core storage.
Sign-in uses industry-standard authentication. Inside your workspace, access is scoped to your organization — team members only see data for the org they belong to.
Admins manage Settings (including billing), teammates, deadlines, and system-type changes, and can review the workspace audit log. Members can work on compliance day to day — inventory, classification, obligations, PDF exports, and the Compliance Advisor — but cannot change workspace Settings. Workspace admins can request single sign-on (SSO) for Okta, Microsoft Entra ID, Google Workspace, and other identity providers from Settings → Team.
Data is encrypted in transit (HTTPS/TLS). Our database and storage providers encrypt data at rest as part of their platform security. Evidence files are stored in private buckets, not on public URLs.
We rely on managed database infrastructure with automated backups and monitoring. We design the product to fail safely — for example, dashboard access defaults to locked when authentication or billing state cannot be verified.
We keep workspace data while your subscription or trial is active. Workspace admins can export data from Settings before leaving. When you delete a workspace, we remove database rows and stored files within a reasonable period, except billing or legal records we must retain. Expired anonymous scan sessions and expired client share links are cleaned up automatically as described in our Privacy Policy.
Organization admins can open the workspace audit log to see who changed what and when — inventory updates, classifications, obligation checklists, deadline edits, document generation, and team or settings changes. Events are append-only and scoped to your org.
The audit log complements exported PDFs. It is not a substitute for your own legal records-retention policies.
Authentication, database, email, billing, hosting, and Advisor inference are provided by named vendors under our customer DPA. We publish the current list with purpose and location notes so your questionnaires stay accurate. View sub-processors
If you notice something that does not look right — a suspected security issue, unexpected access, or anything that worries your team — email us with details. We take reports seriously and will follow up promptly.
Security contact: hello@conformant.eu
Last updated: July 2026
Questions? Get in touch.