Company / Security

Posture, not promises.

SOC 2 type II in progress, GDPR-compliant by design, with EU data residency for EU customers, sub-processors listed below, and security questionnaires answered within the working week.

SOC 2 type II in progress · GDPR by design · EU data residency · sub-processors disclosed

Compliance#

  • SOC 2 type II: audit in progress. Letter of attestation available under NDA once issued.
  • GDPR: compliant by design. Data Processing Agreement available on request (also linked from the DPA page).
  • CCPA: compliant for California-resident buyers configuring on customer-facing surfaces.
  • ISO 27001: in scope for the year after SOC 2 closes.

Data residency#

EU customer data stays in the EU. AWS regions: primary in eu-central-1 (Frankfurt), failover in eu-west-1 (Dublin). The marketing site (this domain) is global via CloudFront with EU-default routing.

For non-EU customers, US regions are available on request.

Sub-processors#

Updated as the platform evolves. Current list:

  • AWS (compute, storage, CDN, lambdas). Region: eu-central-1 primary, eu-west-1 failover.
  • Stripe (payments processing, when enabled).
  • Mollie (payments processing, EU-region-specific, when enabled).
  • Sentry (error tracking; PII scrubbed before transmission).
  • PostHog (product analytics on the seller-facing platform; not the configurator).
  • Meta Conversions API (marketing telemetry, optional, configurable per-customer; respects GPC and DNT).

Per-customer sub-processor additions (custom CRMs, custom ERPs) are disclosed to the customer’s DPO at integration time.

Encryption#

  • In transit: TLS 1.2 minimum, TLS 1.3 preferred. HSTS preload-listed.
  • At rest: AES-256 on S3 (SSE-S3 or SSE-KMS depending on workload). RDS-equivalent for relational data.
  • Secrets: AWS Secrets Manager, rotated. No long-lived static keys in code.

Access control#

  • Customer access: SSO via SAML or OIDC, available on enterprise plans. Per-role permissions on dealer hub and configurator authoring.
  • SaleSqueze access: production access limited to on-call engineers, time-boxed sessions, audit logged. Customer data is not accessed for any reason without explicit customer permission.

Incident response#

24-hour disclosure to affected customers (or shorter per regulation). Quarterly tabletop exercises. Post-incident write-ups published to enterprise customers under NDA.

  • Privacy policy. the public statement of what we collect and why.
  • Terms of service. the customer-side contract.
  • DPA. data processing terms for the GDPR-applicable customers.
  • Cookie policy. what runs in the buyer’s browser, why, and how to opt out.
  • Accessibility. WCAG conformance posture.
  • SLA. uptime, support response times, incident comms.

Start selling visually.

See SaleSqueze on your own product line.

Book a Demo
  • Live in 7 days
  • The build is free
  • Ready-made templates