Security & Privacy
at ISMS Copilot
We build compliance tools for security professionals. That means your data security is not just a feature — it's our foundation.
Full GDPR compliance with DPA available
Database and file storage in the EU, plus EU AI processing with Advanced Data Protection
Infrastructure providers (AWS, Supabase) hold SOC 2 Type II attestations
Independent web application pentest by NevaSec. No findings of critical or high severity.
Security Practices
How we protect your compliance data
Encryption in Transit
All connections secured with TLS 1.3. No unencrypted data ever leaves your browser.
Encryption at Rest
AES-256 encryption for all stored data. Database and file storage encrypted by default.
Row-Level Security
Database-enforced access isolation. Users can only access their own data at the database level.
EU Data Center
Primary infrastructure hosted in Frankfurt, Germany (AWS EU-Central-1). Database and file storage stay in the EU.
SOC 2 Type II Infrastructure
Built on Supabase and AWS, both SOC 2 Type II attested. Enterprise-grade security by default.
No AI Training
Your data is never used to train AI models. This is prevented through provider commercial terms and account-level training-disallowed controls.
PII Redaction
Built-in redaction helps strip personal data before it reaches AI providers, where enabled.
Independent Penetration Test: NevaSec, April 2026
NevaSec performed an external penetration test of our web application, REST API, and AI backend in April 2026. No unauthenticated exploitation path and no immediate account-compromise scenario were identified. The medium-severity finding has been remediated, and remediation work for the remaining low-severity items is underway.
Data Residency
Choose where your data is processed
Standard Mode
- DatabaseEUEU (Frankfurt)
- File StorageEUEU (Frankfurt)
- AI ProcessingUSxAI (Grok) via OpenRouter's zero-retention xAI (ZDR) endpoint (current default for paid Fast/Think/Beyond), with Anthropic Claude as automatic failover; OpenRouter eight-provider allowlist (ZDR enforced)
- AI RetentionZero retention (xAI ZDR default). Anthropic failover-served traffic: ~30 days ordinary deletion; safety-flagged content up to 2 years, safety scores up to 7 years. Web-search queries route via Mistral (standard retention, see DPA).
- Content ModerationEUMistral AI
- AI FailoverEUMistral AI (EU)
- Data SafeguardsStandard Contractual Clauses
Advanced Data Protection
- DatabaseEUEU (Frankfurt)
- File StorageEUEU (Frankfurt)
- AI ProcessingEUMistral AI only
- AI RetentionZero retention
- Content ModerationEUMistral AI
- AI FailoverEUMistral AI (EU)
- US Data TransfersUS AI processing eliminated (email delivery still uses US providers under SCCs)
Database and file storage are always hosted in the EU (Frankfurt, Germany), regardless of the selected mode.
Moderation metadata is retained 12 months for safety review (no message content). Threads with flagged messages are locked from user deletion. See DPA §2.8.
Email addresses are processed by SendGrid and Kit (US) with Standard Contractual Clauses in all modes.
Subprocessors
Third-party services that process data on our behalf
| Service | Purpose | Location | Retention |
|---|---|---|---|
| Supabase | Database & Authentication | EUEU (Frankfurt, Germany) | User-controlled |
| AWS | Infrastructure | EUEU (Frankfurt, Germany) | User-controlled |
| Anthropic (Claude) | AI Processing: automatic failover for paid Fast/Think/Beyond and permitted non-ADP destination (ADP off); no longer the default | USUnited States | ~30 days ordinary deletion; safety-flagged content up to 2 years, safety scores up to 7 years; never training |
| OpenRouter | Routing aggregator (ADP off): routes only to the eight allowlisted underlying providers below (including xAI); mandatory Zero Data Retention enforced at account level | USUnited States | Zero retention (mandatory at OpenRouter account level) |
| ↳ Inceptron | AI Processing (via OpenRouter, ZDR enforced) | EUSweden (EU) | Zero retention |
| ↳ DeepInfra | AI Processing (via OpenRouter, ZDR enforced) | USUnited States | Zero retention |
| ↳ Cerebras | AI Processing (via OpenRouter, ZDR enforced) | USUnited States | Zero retention |
| ↳ Google Vertex | AI Processing (via OpenRouter, ZDR enforced) | USUnited States | Zero retention |
| ↳ Together AI | AI Processing (via OpenRouter, ZDR enforced; added 2026-05-25) | USUnited States (default North America data centers per Together docs; OR aggregator does not pin region per request) | Zero retention |
| ↳ Fireworks AI | AI Processing (via OpenRouter, ZDR enforced; added 2026-05-25) | USUnited States — multi-region fleet (US, EU Frankfurt + Iceland, APAC Tokyo only — no PRC infrastructure; OR aggregator does not pin region per request) | Zero retention |
| ↳ Nebius | AI Processing (via OpenRouter, ZDR enforced; added 2026-05-25) | GlobalNetherlands HQ; primary inference in Finland (EU) with US secondary per Nebius docs (OR aggregator does not pin region per request) | Zero retention |
| ↳ xAI (Grok) | AI Processing (via OpenRouter, ZDR enforced). Current default for paid plans (Plus and above, ADP off) for chat Fast/Think and the Beyond assistant, with Anthropic as automatic failover; also serves the logged-out risk-analysis demo. | USUnited States (OpenRouter-published footprint; inference region not pinned via OpenRouter) | Zero retention (xAI (ZDR) endpoint, verified 2026-07-19) |
| Mistral AI | AI Processing (ADP), content moderation, failover, conversation summaries: EU zero-retention. Authenticated web-search discovery (ADP off) runs on Mistral's stateful endpoint using Brave (US) as Mistral's sub-processor, so it is not EU-only and uses standard retention (see DPA). | EUEU (Frankfurt); web-search discovery reaches Brave (US) via Mistral | Zero retention (inference/moderation); standard retention for web-search discovery via Brave (US) |
| Fly.io | Chat API Service | EUEU deployment | Access logs 30-90 days |
| ConvertAPI | Document Format Conversion (ISO 27001:2022) | EUEU (Frankfurt) | Zero retention (in-memory only) |
| Stripe | Payment Processing (PCI DSS Level 1) | GlobalGlobal (EU DPA) | Billing records 7 years (anonymized) |
| PostHog | Product Analytics | EUEU (Frankfurt) | Up to 7 years (anonymized) |
| Sentry | Error Tracking & Monitoring | EUGermany | Up to 90 days (PII-scrubbed, no IP stored) |
| Vercel | Web Hosting & Analytics | GlobalGlobal CDN | Per Vercel policy (cookieless analytics) |
| SendGrid (Twilio) | Legal Update Emails | USUnited States | Until account deletion or unsubscribe |
| Kit (ConvertKit) | Onboarding & Product Emails | USUnited States | Until account deletion or unsubscribe |
Customer-Activated Integrations
Active for your data only when your organization installs them.
| Service | Purpose | Location | Retention |
|---|---|---|---|
| Slack Technologies, Inc. | heygrc bot — receives messages addressed to the bot, posts AI responses back. Activated only when a paid-organization owner installs from the Connectors page; uninstall hard-deletes integration records. | USUnited States | Active while integration installed |
Last updated: July 2026 · Materially adverse sub-processor changes: 30 days advance notice by email and in-app. Control-neutral changes are announced by publication in this Trust Center and the change log (DPA 2.4). A change is control-neutral when it does not materially weaken retention, training, publication, security, transfer, or jurisdiction controls and does not expand the categories of data processed. Customer-Activated Integrations are not subject to this rule because no data flows until your organization explicitly installs them.
Third-Party Content
Open-source and Creative Commons content incorporated into the platform, with attribution to the original maintainers.
SOC 2 Report Review skill
Adapts the SOC 2 Reliability Rubric maintained by the SOC 2 Quality Guild. The 11-signal taxonomy and Structure / Substance / Source pillars are taken from the Guild rubric; the chat workflow, verdicts, and scorecard are this project's adaptation. Per CC BY-SA 4.0 §3(b)(1), this adaptation is also licensed under CC BY-SA 4.0.
Legal Documents
Transparency documentation available for review
Data Processing Agreement
DPA covering GDPR Article 28 requirements
Privacy Policy
How we collect, use, and protect your data
Cookie Policy
How this Trust Center uses cookies and how to manage your choices
Terms of Service
Terms governing the use of ISMS Copilot
Register of Processing Activities
Full RoPA detailing all data processing operations
Intellectual Property Compliance
How we acquire standards, protect IP rights in AI guidance, and credit third-party content
Legal Document Change Log
Cumulative summary of revisions to our legal documents