Security, compliance, and data protection at PolicySuite. Everything you need to evaluate our platform for your organisation.
We implement industry-standard security controls and maintain alignment with major compliance frameworks.
Controls aligned with Trust Services Criteria for security, availability, and confidentiality.
AlignedFull compliance with EU and UK General Data Protection Regulation requirements.
CompliantInformation security management controls aligned with Annex A requirements.
AlignedComplete protection against all top 10 web application security vulnerabilities.
ProtectedEnterprise-grade security built into every layer of our platform.
Your data stays in the EU with full GDPR compliance.
All customer data is stored and processed in Frankfurt, Germany. No data leaves the European Union.
Standard DPA available for all customers. Enterprise customers can request customised terms.
Request DPA →GDPR-compliant data export and erasure on request. Full deletion within 30 days with verification.
Multi-tenant architecture with strict organisation-level data isolation. Your data is never accessible to other customers.
Third-party services that process customer data on our behalf.
| Service | Purpose | Location | Data Processed |
|---|---|---|---|
| Render | Cloud hosting infrastructure | Frankfurt, Germany | All application data |
| Stripe | Payment processing | EU (Ireland) | Payment information only |
| Resend | Transactional email delivery | EU | Email addresses, names |
| Sentry | Error monitoring | EU (Germany) | Error logs (no PII) |
| OpenAI | AI policy generation (optional) | USA* | Policy content only (when used) |
*AI features are optional and disabled by default. Data is not used for training. Last updated: January 2026
We maintain a rigorous security testing programme.
Security assessment reports are available under NDA for enterprise customers evaluating PolicySuite.
Request security documentation for your compliance review.
Pre-completed responses to common security questionnaires (SIG, CAIQ, custom).
RequestFor security inquiries, vulnerability reports, or compliance questions.
PGP key available on request. We respond within 48 hours.