Last verified: 14 September 2026

Technical and organisational measures

Where the data is

Isolating data between clients

Encryption in transit

Authentication and sessions

Platform team access to client data

Minimisation

Retention and erasure

Backups

Personal data breaches

What we do not have

  • We have no ISO 27001 or SOC 2 certification. We compensate with transparency: the supplier list by name, this document and the data processing agreement, all public.
  • We do not claim encryption at rest. It is not confirmed in the stack we use, so we do not state it.
  • We do not require two-factor authentication for administrators. Administrative access is protected by a separate, short, logged session rather than a second factor.
  • We have no backup outside the server. Restoring is proven, but on copies that sit next to the original.
  • We have no external availability monitoring, so we promise no availability level and cannot guarantee that we learn of an outage immediately.
Technical and organisational measures · Emisar APP