Trust center
The strongest claim a compliance product can make is that its makers trust it with their own compliance. Our ISO 27001 management system — scope, risks, controls, audits, reviews — lives inside StandardOS itself, and our certification audit is in progress with an accredited body. Until that certificate is on this page, here is something better than a badge: exactly how the service is secured and operated.
Deliberately few. Changes are announced here with prior notice to customers.
| Provider | Role | Processing location |
|---|---|---|
| Supabase | Database, auth, storage | EU (Frankfurt) |
| Vercel | Application hosting & delivery | EU serving; global CDN for static assets |
| Stripe | Payments (card data never touches our servers) | EU/US — DPF & SCCs |
| Resend | Transactional email | EU region |
Found a vulnerability? Tell us at security@standardos.com and we'll acknowledge within one business day. We won't take legal action against good-faith research, we'll keep you informed as we fix, and we credit reporters who want credit. Please avoid accessing other organizations' data — the row-level security should make that impossible, and we'd genuinely like to know if it doesn't.
Questions a security review needs answered — questionnaires, our DPA, architecture detail? Email security@standardos.com. A founder answers, within one business day.