Compliance & certifications

DBC1 maintains the compliance commitments expected of enterprise infrastructure providers.

GDPR
Compliant

DBC1 processes employee data under the EU General Data Protection Regulation. Data Protection Officer designated. Records of processing maintained. Data subject requests honored within 30 days.

Data Processing Agreement
Available

Standard DPA available on request. Includes Standard Contractual Clauses for cross-border data transfers. Signed during contracting, before any production data is processed.

Request DPA →
SOC 2
In preparation

In preparation. The auditor and engagement are not yet confirmed and no report has been issued.

ISO 27001
In preparation

In preparation. The certification body is not yet confirmed. Until a certificate is issued we describe our controls as aligned with Annex A and represent nothing further.

SOC 2 and ISO 27001 reports will be available on request once issued. Until then, reviewers may request the latest progress report under NDA.

Data protection

Encryption, data residency, and disaster recovery for customer data stored and processed by DBC1.

Encryption in transit

All traffic to and from DBC1 is encrypted using TLS 1.3 with modern cipher suites on our public web and application endpoints, with HTTP redirected to HTTPS. Enforcing encryption on every internal service-to-service connection is in progress and tracked in our ISO 27001 programme.

Encryption at rest

Customer data is encrypted at rest using AES-256. Encryption keys are managed in Google Cloud KMS. Database backups, file storage, and analytics stores are all encrypted using the same scheme.

Data residency

Primary hosting is in Google Cloud, three EU regions — europe-west1 (Belgium), europe-central2 (Poland) and europe-west3 (Germany). Customer data is stored and processed inside the EU. We do not offer non-EU regions, on request or otherwise.

Backup & disaster recovery

Our document database runs as a three-node replica set. Backup retention, point-in-time recovery and documented restore testing are being brought to a consistent standard across all production data stores as part of our ISO 27001 programme. We do not publish an RTO or RPO target until that work is complete and tested.

Access & authentication

How identities, permissions, and administrative actions are managed in DBC1.

Single sign-on

SAML 2.0 single sign-on is not available today. It is on the roadmap for the Enterprise tier. Until it ships, our team maintains the mirror of your employee record with you and card state follows the changes you send us.

User provisioning

SCIM 2.0 automated provisioning is not available today and is on the Enterprise roadmap. Joiner, mover and leaver events are actioned by our team from the employee record you nominate as source of truth.

Role-based access

Administrative actions are gated by role. The implemented roles are Super Admin, Company Manager, Group Manager and Reseller. Custom roles are not available today. A full role-permission matrix is available to reviewers under NDA.

Multi-factor authentication

DBC1 does not yet offer TOTP or WebAuthn second factors on administrative accounts. Multi-factor authentication is on the roadmap alongside SSO.

Audit logs

Every administrative action is logged with actor, action, target and timestamp. Logs are exportable on request. Retention periods and SIEM forwarding are being formalised as part of our ISO 27001 programme.

Session management

Administrative sessions expire after a period of inactivity. Re-authentication for sensitive actions and administrator-initiated session revocation are not built today.

Infrastructure & operations

How DBC1 runs, monitors, and tests its production environment.

Hosting

DBC1 runs on Google Cloud. Customer data is hosted in three EU regions: europe-west1 (Belgium), europe-central2 (Poland) and europe-west3 (Germany). Google Cloud holds its own SOC 1, SOC 2, ISO 27001, ISO 27017, ISO 27018 and PCI DSS certifications.

Availability

We do not publish a status page or a contractual uptime figure today. High-severity incidents affecting your service are reported directly to your named contact.

Monitoring & logging

Application, infrastructure and security logs are centralised in Google Cloud Logging. Infrastructure alerting and error notification are in place. Full synthetic monitoring across all services and a formal on-call rotation are being established as part of our ISO 27001 programme.

Vulnerability management

Automated dependency, container and secret scanning is being added across our build pipelines, with defined patch severity levels and timelines, as part of our ISO 27001 programme. We do not yet publish a patch SLA.

Penetration testing

Security testing to date has been conducted internally. An independent third-party penetration test is being commissioned; no external report exists yet. Our internal test summary is available to reviewers under NDA.

Personnel security

Everyone with production access signs a confidentiality agreement. Background checks, mandatory annual security awareness training and quarterly privileged-access reviews are being formalised and evidenced as part of our ISO 27001 programme.

Incident response

What happens when something goes wrong - and how quickly you'll know.

DBC1 is formalising a documented incident response plan covering detection, triage, containment, customer notification and post-incident review, as part of our ISO 27001 programme. The commitments below apply today.

Data breach notification
In the event of a confirmed personal data breach affecting a customer, DBC1 notifies the customer's designated contact without undue delay and no later than 72 hours after becoming aware of the incident.
Operational incidents
For high-severity incidents affecting service availability, we notify the customer's designated contact as soon as impact is confirmed.
What you'll receive
Initial notification includes the nature of the incident, categories of data potentially affected, likely consequences, measures taken or proposed, and a primary contact for follow-up. A full post-incident report is delivered after resolution.
Reporting to us
If you observe behavior that may indicate a security incident in DBC1, contact security@dbc1.com immediately. PGP key available on request .

Sub-processors

The categories of third-party service that process customer data. Each is bound by a data processing agreement mirroring the protections in our DPA with you. Named identities, entity locations and transfer mechanisms are listed in Annex III of the DPA and released under NDA.

CategoryPurposeLocation
Cloud hosting and infrastructureApplication hosting, database and file storageEU
Transactional emailTransactional emailAnnex III
Customer support toolingCustomer supportAnnex III
Product analyticsProduct analyticsAnnex III
Error and performance monitoringError and performance monitoringAnnex III
Billing and subscription managementBilling and subscription managementAnnex III
CRM platforms you choose to connectSales and lead management, including our own prospect recordsYour choice
Notification of changes. New sub-processors are notified in writing to the contact designated in your account before they begin processing customer data, on the notice period set out in the DPA. To subscribe to sub-processor updates, email security@dbc1.com.

Contact & responsible disclosure

How to reach the security team and how we work with researchers.

Security inquiries

Security questionnaires, vendor reviews, additional documentation requests.

Data protection inquiries

GDPR questions, data subject access requests, DPO matters.

Responsible disclosure

If you discover a vulnerability in DBC1, report it to security@dbc1.com. We commit to:

  • Acknowledging your report promptly and confirming receipt2 business days
  • Investigating and confirming the vulnerability, and telling you what we find
  • Keeping you informed throughout remediation
  • Not pursuing legal action against good-faith research

Please do not publicly disclose the vulnerability until we have had reasonable opportunity to remediate. We do not operate a paid bug bounty programme but recognise researchers in public acknowledgments on request.