Company / Security
Posture, not promises.
SOC 2 type II in progress, GDPR-compliant by design, with EU data residency for EU customers, sub-processors listed below, and security questionnaires answered within the working week.
SOC 2 type II in progress · GDPR by design · EU data residency · sub-processors disclosed
Compliance#
- SOC 2 type II: audit in progress. Letter of attestation available under NDA once issued.
- GDPR: compliant by design. Data Processing Agreement available on request (also linked from the DPA page).
- CCPA: compliant for California-resident buyers configuring on customer-facing surfaces.
- ISO 27001: in scope for the year after SOC 2 closes.
Data residency#
EU customer data stays in the EU. AWS regions: primary in eu-central-1 (Frankfurt), failover in eu-west-1 (Dublin). The marketing site (this domain) is global via CloudFront with EU-default routing.
For non-EU customers, US regions are available on request.
Sub-processors#
Updated as the platform evolves. Current list:
- AWS (compute, storage, CDN, lambdas). Region: eu-central-1 primary, eu-west-1 failover.
- Stripe (payments processing, when enabled).
- Mollie (payments processing, EU-region-specific, when enabled).
- Sentry (error tracking; PII scrubbed before transmission).
- PostHog (product analytics on the seller-facing platform; not the configurator).
- Meta Conversions API (marketing telemetry, optional, configurable per-customer; respects GPC and DNT).
Per-customer sub-processor additions (custom CRMs, custom ERPs) are disclosed to the customer’s DPO at integration time.
Encryption#
- In transit: TLS 1.2 minimum, TLS 1.3 preferred. HSTS preload-listed.
- At rest: AES-256 on S3 (SSE-S3 or SSE-KMS depending on workload). RDS-equivalent for relational data.
- Secrets: AWS Secrets Manager, rotated. No long-lived static keys in code.
Access control#
- Customer access: SSO via SAML or OIDC, available on enterprise plans. Per-role permissions on dealer hub and configurator authoring.
- SaleSqueze access: production access limited to on-call engineers, time-boxed sessions, audit logged. Customer data is not accessed for any reason without explicit customer permission.
Incident response#
24-hour disclosure to affected customers (or shorter per regulation). Quarterly tabletop exercises. Post-incident write-ups published to enterprise customers under NDA.
Reading the rest of the legal posture#
- Privacy policy. the public statement of what we collect and why.
- Terms of service. the customer-side contract.
- DPA. data processing terms for the GDPR-applicable customers.
- Cookie policy. what runs in the buyer’s browser, why, and how to opt out.
- Accessibility. WCAG conformance posture.
- SLA. uptime, support response times, incident comms.
Start selling visually.
See SaleSqueze on your own product line.
By clicking “Book a Demo” you agree to our Terms of Service and Privacy Policy.
- Live in 7 days
- The build is free
- Ready-made templates