ISMS Copilot
Trust Center

Security & Privacy

at ISMS Copilot

We build compliance tools for security professionals. That means your data security is not just a feature — it's our foundation.

GDPR Compliant

Full GDPR compliance with DPA available

Active
EU-Only Mode Available

Database and file storage in the EU, plus EU AI processing with Advanced Data Protection

Active
SOC 2 Type II Infrastructure

Infrastructure providers (AWS, Supabase) hold SOC 2 Type II attestations

Active
External Pentest 2026

Independent web application pentest by NevaSec. No findings of critical or high severity.

Active

Security Practices

How we protect your compliance data

Encryption in Transit

All connections secured with TLS 1.3. No unencrypted data ever leaves your browser.

Encryption at Rest

AES-256 encryption for all stored data. Database and file storage encrypted by default.

Row-Level Security

Database-enforced access isolation. Users can only access their own data at the database level.

EU Data Center

Primary infrastructure hosted in Frankfurt, Germany (AWS EU-Central-1). Database and file storage stay in the EU.

SOC 2 Type II Infrastructure

Built on Supabase and AWS, both SOC 2 Type II attested. Enterprise-grade security by default.

No AI Training

Your data is never used to train AI models. This is prevented through provider commercial terms and account-level training-disallowed controls.

PII Redaction

Built-in redaction helps strip personal data before it reaches AI providers, where enabled.

Independent Penetration Test: NevaSec, April 2026

NevaSec performed an external penetration test of our web application, REST API, and AI backend in April 2026. No unauthenticated exploitation path and no immediate account-compromise scenario were identified. The medium-severity finding has been remediated, and remediation work for the remaining low-severity items is underway.

Data Residency

Choose where your data is processed

Default

Standard Mode

  • DatabaseEUEU (Frankfurt)
  • File StorageEUEU (Frankfurt)
  • AI ProcessingUSxAI (Grok) via OpenRouter's zero-retention xAI (ZDR) endpoint (current default for paid Fast/Think/Beyond), with Anthropic Claude as automatic failover; OpenRouter eight-provider allowlist (ZDR enforced)
  • AI RetentionZero retention (xAI ZDR default). Anthropic failover-served traffic: ~30 days ordinary deletion; safety-flagged content up to 2 years, safety scores up to 7 years. Web-search queries route via Mistral (standard retention, see DPA).
  • Content ModerationEUMistral AI
  • AI FailoverEUMistral AI (EU)
  • Data SafeguardsStandard Contractual Clauses
Recommended

Advanced Data Protection

  • DatabaseEUEU (Frankfurt)
  • File StorageEUEU (Frankfurt)
  • AI ProcessingEUMistral AI only
  • AI RetentionZero retention
  • Content ModerationEUMistral AI
  • AI FailoverEUMistral AI (EU)
  • US Data TransfersUS AI processing eliminated (email delivery still uses US providers under SCCs)

Database and file storage are always hosted in the EU (Frankfurt, Germany), regardless of the selected mode.

Moderation metadata is retained 12 months for safety review (no message content). Threads with flagged messages are locked from user deletion. See DPA §2.8.

Email addresses are processed by SendGrid and Kit (US) with Standard Contractual Clauses in all modes.

Subprocessors

Third-party services that process data on our behalf

ServicePurposeLocationRetention
SupabaseDatabase & AuthenticationEUEU (Frankfurt, Germany)User-controlled
AWSInfrastructureEUEU (Frankfurt, Germany)User-controlled
Anthropic (Claude)AI Processing: automatic failover for paid Fast/Think/Beyond and permitted non-ADP destination (ADP off); no longer the defaultUSUnited States~30 days ordinary deletion; safety-flagged content up to 2 years, safety scores up to 7 years; never training
OpenRouterRouting aggregator (ADP off): routes only to the eight allowlisted underlying providers below (including xAI); mandatory Zero Data Retention enforced at account levelUSUnited StatesZero retention (mandatory at OpenRouter account level)
↳ InceptronAI Processing (via OpenRouter, ZDR enforced)EUSweden (EU)Zero retention
↳ DeepInfraAI Processing (via OpenRouter, ZDR enforced)USUnited StatesZero retention
↳ CerebrasAI Processing (via OpenRouter, ZDR enforced)USUnited StatesZero retention
↳ Google VertexAI Processing (via OpenRouter, ZDR enforced)USUnited StatesZero retention
↳ Together AIAI Processing (via OpenRouter, ZDR enforced; added 2026-05-25)USUnited States (default North America data centers per Together docs; OR aggregator does not pin region per request)Zero retention
↳ Fireworks AIAI Processing (via OpenRouter, ZDR enforced; added 2026-05-25)USUnited States — multi-region fleet (US, EU Frankfurt + Iceland, APAC Tokyo only — no PRC infrastructure; OR aggregator does not pin region per request)Zero retention
↳ NebiusAI Processing (via OpenRouter, ZDR enforced; added 2026-05-25)GlobalNetherlands HQ; primary inference in Finland (EU) with US secondary per Nebius docs (OR aggregator does not pin region per request)Zero retention
↳ xAI (Grok)AI Processing (via OpenRouter, ZDR enforced). Current default for paid plans (Plus and above, ADP off) for chat Fast/Think and the Beyond assistant, with Anthropic as automatic failover; also serves the logged-out risk-analysis demo.USUnited States (OpenRouter-published footprint; inference region not pinned via OpenRouter)Zero retention (xAI (ZDR) endpoint, verified 2026-07-19)
Mistral AIAI Processing (ADP), content moderation, failover, conversation summaries: EU zero-retention. Authenticated web-search discovery (ADP off) runs on Mistral's stateful endpoint using Brave (US) as Mistral's sub-processor, so it is not EU-only and uses standard retention (see DPA).EUEU (Frankfurt); web-search discovery reaches Brave (US) via MistralZero retention (inference/moderation); standard retention for web-search discovery via Brave (US)
Fly.ioChat API ServiceEUEU deploymentAccess logs 30-90 days
ConvertAPIDocument Format Conversion (ISO 27001:2022)EUEU (Frankfurt)Zero retention (in-memory only)
StripePayment Processing (PCI DSS Level 1)GlobalGlobal (EU DPA)Billing records 7 years (anonymized)
PostHogProduct AnalyticsEUEU (Frankfurt)Up to 7 years (anonymized)
SentryError Tracking & MonitoringEUGermanyUp to 90 days (PII-scrubbed, no IP stored)
VercelWeb Hosting & AnalyticsGlobalGlobal CDNPer Vercel policy (cookieless analytics)
SendGrid (Twilio)Legal Update EmailsUSUnited StatesUntil account deletion or unsubscribe
Kit (ConvertKit)Onboarding & Product EmailsUSUnited StatesUntil account deletion or unsubscribe

Customer-Activated Integrations

Active for your data only when your organization installs them.

ServicePurposeLocationRetention
Slack Technologies, Inc.heygrc bot — receives messages addressed to the bot, posts AI responses back. Activated only when a paid-organization owner installs from the Connectors page; uninstall hard-deletes integration records.USUnited StatesActive while integration installed

Last updated: July 2026 · Materially adverse sub-processor changes: 30 days advance notice by email and in-app. Control-neutral changes are announced by publication in this Trust Center and the change log (DPA 2.4). A change is control-neutral when it does not materially weaken retention, training, publication, security, transfer, or jurisdiction controls and does not expand the categories of data processed. Customer-Activated Integrations are not subject to this rule because no data flows until your organization explicitly installs them.

Third-Party Content

Open-source and Creative Commons content incorporated into the platform, with attribution to the original maintainers.

SOC 2 Report Review skill

Adapts the SOC 2 Reliability Rubric maintained by the SOC 2 Quality Guild. The 11-signal taxonomy and Structure / Substance / Source pillars are taken from the Guild rubric; the chat workflow, verdicts, and scorecard are this project's adaptation. Per CC BY-SA 4.0 §3(b)(1), this adaptation is also licensed under CC BY-SA 4.0.