Trust center

We run StandardOS on StandardOS

The strongest claim a compliance product can make is that its makers trust it with their own compliance. Our ISO 27001 management system — scope, risks, controls, audits, reviews — lives inside StandardOS itself, and our certification audit is in progress with an accredited body. Until that certificate is on this page, here is something better than a badge: exactly how the service is secured and operated.

Infrastructure & hosting

Data residency
All customer data is stored in the EU (Supabase, Frankfurt region). We choose EU regions wherever the service touches customer records.
Delivery
Applications are served over TLS 1.2+ only; HSTS enforced. Static assets via CDN; no customer records at the edge.
Backups
Point-in-time recovery on the primary database; restore drills are performed quarterly and logged — in StandardOS, as evidence.

Record integrity — our differentiator

Tamper-evident audit trail
Every material change is written to an append-only, hash-chained audit log. Each entry carries the hash of the previous one; rewriting history breaks the chain visibly.
Anchoring
The chain head is anchored daily to write-once storage, so even we cannot silently alter the past.
Verifiability
Exports carry the hashes. Your auditor — or you — can verify independently that records haven't been rewritten. No other tool in this market offers customer-verifiable history.

Access control

Tenant isolation
Row-level security on every table, enforced in the database itself — not in application code — and tested in CI (pgTAP) on every change.
Authentication
Password sign-in with modern hashing, or SSO via Microsoft and Google. Sessions are short-lived and refreshed.
Our own access
Least-privilege staff roles; production access is logged in the same tamper-evident trail we give customers.

Development practices

Change control
Every change ships through CI: type checks, tests, database policy tests, and secret scanning on every commit.
Dependencies
Locked and reviewed; automated vulnerability alerts on the full dependency graph.
AI discipline
AI-assisted output in the product is always a labeled draft until a human confirms it. The same rule applies to how we build.

Privacy & data protection

GDPR
Danish controller; DPA (Art. 28) available to every customer, not just enterprise plans. Details in the Privacy Policy.
No tracking
No analytics or advertising trackers on this site; no cookie banner because there is nothing to consent to.
Exit
Full one-click export in open formats at any time — during trial, while subscribed, and for 90 days after cancellation. Lock-in is not a retention strategy.

Subprocessors

Deliberately few. Changes are announced here with prior notice to customers.

ProviderRoleProcessing location
SupabaseDatabase, auth, storageEU (Frankfurt)
VercelApplication hosting & deliveryEU serving; global CDN for static assets
StripePayments (card data never touches our servers)EU/US — DPF & SCCs
ResendTransactional emailEU region

Responsible disclosure

Found a vulnerability? Tell us at security@standardos.com and we'll acknowledge within one business day. We won't take legal action against good-faith research, we'll keep you informed as we fix, and we credit reporters who want credit. Please avoid accessing other organizations' data — the row-level security should make that impossible, and we'd genuinely like to know if it doesn't.

Questions a security review needs answered — questionnaires, our DPA, architecture detail? Email security@standardos.com. A founder answers, within one business day.