Transparency in security, compliance, and data protection. View our certifications, security controls, and subprocessor information.
Last updated: February 2026
Industry certifications and compliance standards
Cloud Application Security Assessment certified Tier 2 (Lab Tested - Lab Verified) under the App Defense Alliance, independently assessed by TAC Security against the OWASP ASVS standard. Valid through 15 April 2027.

Singapore CSA Cyber Essentials certification demonstrating baseline cybersecurity hygiene and practices.
Full compliance with Singapore Personal Data Protection Act requirements for data collection, use, and disclosure.
Reports, assessments, and compliance documentation
App Defense Alliance Cloud Application Security Assessment (CASA) Tier 2 Statement of Validation, independently lab-tested and verified by TAC Security. Valid through 15 April 2027.
Full CASA application security scan report (ESOF AppSec / ADA CASA) covering web application, API, and infrastructure security testing against the OWASP ASVS standard. Available for enterprise evaluation under NDA.
CASA TAC Security assessment report covering web application, API, and infrastructure security testing. Score: 9.7/10. All identified vulnerabilities have been patched.
Standard contractual clauses for data processing, GDPR and PDPA compliant terms for enterprise customers.
Pre-filled security questionnaire based on SIG Lite and CAIQ formats. Available for enterprise evaluation.
Service Organization Control audit report covering security, availability, and confidentiality.
43 of 44 controls implemented
Comprehensive documentation of our security practices
Standards and security configurations for cloud and on-premise assets
Data backup procedures, retention periods, and disaster recovery
Asset lifecycle, onboarding, and secure disposal procedures
Data governance, retention periods, and secure deletion practices
Device security, antivirus, and endpoint management
User provisioning, access control, and authentication
Data protection impact assessments and privacy controls
AI governance, explainability, and ethical guidelines
Business conduct, data protection, and responsible business commitments
Zero tolerance for bribery, AML/CFT controls, and sanctions compliance
Confidential, anonymous reporting for employees and third parties
PDPA governance: DPO, safeguards, transfers, breach response, retention
Environment, labour standards, human rights, and supply chain responsibility
Storage locations, AI models used, safeguards, and third parties
Third-party service providers we work with
| Provider | Purpose | Certifications | Documentation |
|---|---|---|---|
Hetzner Cloud Kubernetes Compute (Envoy CRM) | Kubernetes compute for Envoy CRM, hosted in Hetzner's Singapore data centre (sin-dc1). | ISO 27001 GDPR | View |
![]() Amazon Web Services (AWS) Database, Backups & Email | Aurora Postgres (Volty), S3 for backups and attachments, and SES for transactional email, all in the Singapore region (ap-southeast-1). | SOC 2 ISO 27001 GDPR HIPAA | View |
![]() Cloudflare CDN, WAF & DDoS Protection | Content delivery network, web application firewall, DDoS mitigation, and Zero Trust operator access. | SOC 2 ISO 27001 PCI DSS | View |
![]() Microsoft Azure Container Registry & Sign-in | Internal container registry for image distribution and Microsoft Entra ID sign-in. No customer data is stored or processed on Azure. | SOC 2 ISO 27001 GDPR HIPAA | View |
Anthropic Large Language Model API | Claude language models for agent reasoning. API access only; no training on customer data. | SOC 2 ISO 27001 | View |
![]() OpenAI Large Language Model API | GPT language models for selected tasks. API data excluded from training by default. | SOC 2 | View |
Google (Gemini) Large Language Model API | Gemini language models for selected tasks. Paid API data not used to train models. | SOC 2 ISO 27001 | View |
SigNoz / Sentry Observability & Monitoring | Application performance monitoring, error tracking, and observability. | SOC 2 | View |
Windmill Secure Automation | Self-hosted workflow automation and orchestration platform. | Self-hosted | View |
Last updated: July 2026. For questions about our subprocessors, contact [email protected]
Have questions about our security practices? Need a custom DPA or security questionnaire? Our team is here to help.