Trusted by
Runs on
Google Cloud
Application hosting, database and file storage — three EU regions
Cloudflare
Edge network, DNS and DDoS protection
Compliance

What is in force today.

Four commitments bind us now, in contract and in code. Two certifications are still in preparation, and we keep those visually separate rather than implying a certificate we do not hold.

GDPR
EU General Data Protection Regulation
Compliant
DPA + SCCs
Signed before any production data is processed
Available
EU only
Three EU regions. No non-EU option, on request or otherwise
Data residency
AES-256
At rest, with TLS 1.3 in transit and keys in Cloud KMS
Encryption
In preparation — no report or certificate has been issued
SOC 2

Programme underway. The auditor and engagement are not yet confirmed. We will publish the report here when one exists.

ISO 27001

Programme underway. The certification body is not yet confirmed. Until a certificate is issued we describe our controls as aligned with Annex A and represent nothing further.

Data residency

Your data stays in the EU. All of it.

Primary hosting is Google Cloud, across three EU regions. Customer data is stored and processed inside the European Union. We do not offer non-EU regions — on request or otherwise.

europe-west1
Belgium
europe-central2
Poland
europe-west3
Germany
Inherited from Google Cloud

Our hosting provider holds SOC 1, SOC 2, ISO 27001, ISO 27017, ISO 27018 and PCI DSS certifications covering the physical and platform layer beneath DBC1. Those are Google’s certifications, not ours — they cover the infrastructure we run on, not the DBC1 application.

Controls

What protects the data today.

Encryption, key management, access control and recovery — as implemented, not as aspired to.

Encryption in transit
TLS 1.3 with modern cipher suites on all public web and application endpoints, with HTTP redirected to HTTPS. Enforcing encryption on every internal service-to-service connection is in progress under our ISO 27001 programme.
Encryption at rest
AES-256. Keys are managed in Google Cloud KMS. Database backups, file storage and analytics stores are all encrypted under the same scheme.
Role-based access
Administrative actions are gated by role: Super Admin, Company Manager, Group Manager and Reseller. Custom roles are not available today. A full role-permission matrix is released to reviewers under NDA.
Monitoring and logging
Application, infrastructure and security logs are centralised in Google Cloud Logging, with infrastructure alerting and error notification in place. Synthetic monitoring and a formal on-call rotation are being established.
Vulnerability management
Automated dependency, container and secret scanning runs against the codebase. Findings are triaged and remediated as part of the development cycle.
Breach notification
On a confirmed personal data breach affecting a customer, we notify the designated contact without undue delay and no later than 72 hours after becoming aware of it.
Not available today — on the Enterprise roadmap
SAML 2.0 single sign-on
SCIM 2.0 automated provisioning
TOTP and WebAuthn second factors
Public status page and contractual uptime

Until these ship, joiner, mover and leaver events are actioned by our team from the employee record you nominate as source of truth, and high-severity incidents are reported directly to your named contact.

Sub-processors

Who else touches the data.

Every sub-processor is bound by a data processing agreement mirroring the protections in our DPA with you. Named identities, entity locations and transfer mechanisms are listed in Annex III and published in the Trust Center.

CategoryPurposeLocation
Cloud hosting and infrastructureApplication hosting, database and file storageEU
Edge network and DNSContent delivery, DNS and DDoS protectionEU / US
Transactional emailCard delivery and system notificationsAnnex III
Customer support toolingSupport requests and in-product messagingEU
Product analytics and monitoringUsage analytics, error and performance monitoringAnnex III
CRM platforms you connectSales and lead managementYour choice
Notification of changes

New sub-processors are notified in writing to your designated data protection contact at least 30 days before we add or replace one, together with a revised annex, and you have a right to object. That notice goes to you directly rather than being published — a change that gives you a right to object should not depend on you noticing a website update.

Trust Center

The evidence, not just the summary.

This page is the overview. Every policy, plan and agreement behind it lives in the Trust Center — most of it open, the rest released on request within one business day. Requests are reviewed, never routed to sales.

Open the Trust Center
Security Whitepaper
Information Security Policy
Access Control Policy
Cryptography Policy
Secure Development Policy
Incident Response Plan
Business Continuity and DR Plan
Physical Security Policy
Third-Party Management Policy
Data Management Policy
Data Processing Agreement
Service Level Agreement
Contact

Reaching the security team.

Questionnaires, vendor reviews and data protection requests go to a named inbox, not a contact form.

Security inquiries

Security questionnaires, vendor reviews, requests for additional documentation.

security@dbc1.com
Data protection inquiries

GDPR questions, data subject access requests, and anything for the Data Protection Officer.

dpo@dbc1.com
Responsible disclosure

Found a vulnerability? Report it to security@dbc1.com. We confirm receipt within 2 business days, investigate and tell you what we find, keep you informed through remediation, and will not pursue legal action against good-faith research. Please give us reasonable opportunity to remediate before publishing. We do not run a paid bounty, but we credit researchers publicly on request.

Still have questions your review board needs answered?

Send the questionnaire. We complete it ourselves, we do not route it through sales, and we answer “not yet” where that is the honest answer.

Email the security team