DBC1 stores employee identity data and runs core enterprise infrastructure. This page documents the controls in place, the certifications underway, and how to reach our security team.
DBC1 maintains the compliance commitments expected of enterprise infrastructure providers.
DBC1 processes employee data under the EU General Data Protection Regulation. Data Protection Officer designated. Records of processing maintained. Data subject requests honored within 30 days.
Standard DPA available on request. Includes Standard Contractual Clauses for cross-border data transfers. Signed during contracting, before any production data is processed.
Request DPA →In preparation. The auditor and engagement are not yet confirmed and no report has been issued.
In preparation. The certification body is not yet confirmed. Until a certificate is issued we describe our controls as aligned with Annex A and represent nothing further.
Encryption, data residency, and disaster recovery for customer data stored and processed by DBC1.
All traffic to and from DBC1 is encrypted using TLS 1.3 with modern cipher suites on our public web and application endpoints, with HTTP redirected to HTTPS. Enforcing encryption on every internal service-to-service connection is in progress and tracked in our ISO 27001 programme.
Customer data is encrypted at rest using AES-256. Encryption keys are managed in Google Cloud KMS. Database backups, file storage, and analytics stores are all encrypted using the same scheme.
Primary hosting is in Google Cloud, three EU regions — europe-west1 (Belgium), europe-central2 (Poland) and europe-west3 (Germany). Customer data is stored and processed inside the EU. We do not offer non-EU regions, on request or otherwise.
Our document database runs as a three-node replica set. Backup retention, point-in-time recovery and documented restore testing are being brought to a consistent standard across all production data stores as part of our ISO 27001 programme. We do not publish an RTO or RPO target until that work is complete and tested.
How identities, permissions, and administrative actions are managed in DBC1.
SAML 2.0 single sign-on is not available today. It is on the roadmap for the Enterprise tier. Until it ships, our team maintains the mirror of your employee record with you and card state follows the changes you send us.
SCIM 2.0 automated provisioning is not available today and is on the Enterprise roadmap. Joiner, mover and leaver events are actioned by our team from the employee record you nominate as source of truth.
Administrative actions are gated by role. The implemented roles are Super Admin, Company Manager, Group Manager and Reseller. Custom roles are not available today. A full role-permission matrix is available to reviewers under NDA.
DBC1 does not yet offer TOTP or WebAuthn second factors on administrative accounts. Multi-factor authentication is on the roadmap alongside SSO.
Every administrative action is logged with actor, action, target and timestamp. Logs are exportable on request. Retention periods and SIEM forwarding are being formalised as part of our ISO 27001 programme.
Administrative sessions expire after a period of inactivity. Re-authentication for sensitive actions and administrator-initiated session revocation are not built today.
How DBC1 runs, monitors, and tests its production environment.
DBC1 runs on Google Cloud. Customer data is hosted in three EU regions: europe-west1 (Belgium), europe-central2 (Poland) and europe-west3 (Germany). Google Cloud holds its own SOC 1, SOC 2, ISO 27001, ISO 27017, ISO 27018 and PCI DSS certifications.
We do not publish a status page or a contractual uptime figure today. High-severity incidents affecting your service are reported directly to your named contact.
Application, infrastructure and security logs are centralised in Google Cloud Logging. Infrastructure alerting and error notification are in place. Full synthetic monitoring across all services and a formal on-call rotation are being established as part of our ISO 27001 programme.
Automated dependency, container and secret scanning is being added across our build pipelines, with defined patch severity levels and timelines, as part of our ISO 27001 programme. We do not yet publish a patch SLA.
Security testing to date has been conducted internally. An independent third-party penetration test is being commissioned; no external report exists yet. Our internal test summary is available to reviewers under NDA.
Everyone with production access signs a confidentiality agreement. Background checks, mandatory annual security awareness training and quarterly privileged-access reviews are being formalised and evidenced as part of our ISO 27001 programme.
What happens when something goes wrong - and how quickly you'll know.
DBC1 is formalising a documented incident response plan covering detection, triage, containment, customer notification and post-incident review, as part of our ISO 27001 programme. The commitments below apply today.
The categories of third-party service that process customer data. Each is bound by a data processing agreement mirroring the protections in our DPA with you. Named identities, entity locations and transfer mechanisms are listed in Annex III of the DPA and released under NDA.
| Category | Purpose | Location |
|---|---|---|
| Cloud hosting and infrastructure | Application hosting, database and file storage | EU |
| Transactional email | Transactional email | Annex III |
| Customer support tooling | Customer support | Annex III |
| Product analytics | Product analytics | Annex III |
| Error and performance monitoring | Error and performance monitoring | Annex III |
| Billing and subscription management | Billing and subscription management | Annex III |
| CRM platforms you choose to connect | Sales and lead management, including our own prospect records | Your choice |
How to reach the security team and how we work with researchers.
Security questionnaires, vendor reviews, additional documentation requests.
security@dbc1.comIf you discover a vulnerability in DBC1, report it to security@dbc1.com. We commit to:
Please do not publicly disclose the vulnerability until we have had reasonable opportunity to remediate. We do not operate a paid bug bounty programme but recognise researchers in public acknowledgments on request.