Stuorio

Trust Center

Our approach to privacy and security across GDPR, SOC 2, and ISO 27001.

GDPR
20 controls
Immutable audit log
Append-only audit trail of mutations and security events, retained for at least 12 months.
Art 5(2)Art 30Art 32Implemented
Login audit + lockout
Every credential sign-in is logged with outcome; lockout after repeated failures.
Art 32Implemented
Password policy
Length, complexity, history, and optional breach-check enforced on every change.
Art 32Implemented
Role-based access control
Fine-grained, feature-scoped permissions with workspace boundaries.
Art 32Implemented
Right to erasure + anonymisation
Self-service account deletion with a configurable grace period; anonymisation fallback for records on legal hold or referenced by business data.
Art 17Implemented
Legal hold
Records can be placed under legal hold to override retention and deletion.
Art 18Implemented
Public legal documents
Versioned privacy policy, terms, DPA, cookie policy, and security overview.
Art 13Art 14Implemented
Data Subject Access Requests (DSAR)
Self-service data export and admin DSAR queue with 30-day SLA tracking.
Art 15Art 20Implemented
Consent + cookie management
Granular consent purposes, append-only consent ledger, and a cookie banner.
Art 6Art 7Implemented
Sub-processor disclosure
Public list of sub-processors with notification mechanism for changes.
Art 28Implemented
Two-factor authentication
TOTP enrolment with single-use backup codes; can be required for admins.
Art 32Implemented
Session management
Active session listing, sign-out everywhere, configurable idle timeout.
Art 32Implemented
Data retention policies
Per-entity retention rules executed by scheduled sweeps and logged for evidence.
Art 5(1)(e)Implemented
Encryption of sensitive fields
AES-256-GCM helper available for OAuth tokens and integration credentials.
Art 32Implemented
Encryption in transit
TLS 1.2+ enforced on all public endpoints; HSTS enabled.
Art 32Documented
Backups
Scheduled workspace backups with retention and restore tooling.
Art 32Implemented
Incident response + breach notification
Incident workflow with 72-hour notification helper for high-severity events.
Art 33Art 34Implemented
Evidence exports for audits
CSV exports of audit log, DSAR log, consent ledger, login audit, and retention sweep history.
Art 30Implemented
Change management
All entity changes logged via change log; release process documented.
Art 32Implemented
Logging and monitoring
Application logs, error events, and external log destinations.
Art 32Implemented
SOC 2
16 controls
Immutable audit log
Append-only audit trail of mutations and security events, retained for at least 12 months.
CC7.2Implemented
Login audit + lockout
Every credential sign-in is logged with outcome; lockout after repeated failures.
CC6.1CC6.8Implemented
Password policy
Length, complexity, history, and optional breach-check enforced on every change.
CC6.1Implemented
Role-based access control
Fine-grained, feature-scoped permissions with workspace boundaries.
CC6.1CC6.3Implemented
Legal hold
Records can be placed under legal hold to override retention and deletion.
CC6.5Implemented
Public legal documents
Versioned privacy policy, terms, DPA, cookie policy, and security overview.
CC2.2Implemented
Two-factor authentication
TOTP enrolment with single-use backup codes; can be required for admins.
CC6.1Implemented
Session management
Active session listing, sign-out everywhere, configurable idle timeout.
CC6.1Implemented
Data retention policies
Per-entity retention rules executed by scheduled sweeps and logged for evidence.
CC6.5Implemented
Encryption of sensitive fields
AES-256-GCM helper available for OAuth tokens and integration credentials.
CC6.7Implemented
Encryption in transit
TLS 1.2+ enforced on all public endpoints; HSTS enabled.
CC6.7Documented
Backups
Scheduled workspace backups with retention and restore tooling.
A1.2Implemented
Incident response + breach notification
Incident workflow with 72-hour notification helper for high-severity events.
CC7.3CC7.4CC7.5Implemented
Evidence exports for audits
CSV exports of audit log, DSAR log, consent ledger, login audit, and retention sweep history.
CC7.2Implemented
Change management
All entity changes logged via change log; release process documented.
CC8.1Implemented
Logging and monitoring
Application logs, error events, and external log destinations.
CC7.1CC7.2Implemented
ISO 27001
20 controls
Immutable audit log
Append-only audit trail of mutations and security events, retained for at least 12 months.
A.12.4Implemented
Login audit + lockout
Every credential sign-in is logged with outcome; lockout after repeated failures.
A.9.4Implemented
Password policy
Length, complexity, history, and optional breach-check enforced on every change.
A.9.4.3Implemented
Role-based access control
Fine-grained, feature-scoped permissions with workspace boundaries.
A.9.2A.9.4Implemented
Right to erasure + anonymisation
Self-service account deletion with a configurable grace period; anonymisation fallback for records on legal hold or referenced by business data.
A.18Implemented
Legal hold
Records can be placed under legal hold to override retention and deletion.
A.18Implemented
Public legal documents
Versioned privacy policy, terms, DPA, cookie policy, and security overview.
A.5Implemented
Data Subject Access Requests (DSAR)
Self-service data export and admin DSAR queue with 30-day SLA tracking.
A.18.1.4Implemented
Consent + cookie management
Granular consent purposes, append-only consent ledger, and a cookie banner.
A.18Implemented
Sub-processor disclosure
Public list of sub-processors with notification mechanism for changes.
A.15Implemented
Two-factor authentication
TOTP enrolment with single-use backup codes; can be required for admins.
A.9.4.2Implemented
Session management
Active session listing, sign-out everywhere, configurable idle timeout.
A.9.4.2Implemented
Data retention policies
Per-entity retention rules executed by scheduled sweeps and logged for evidence.
A.8.3A.18Implemented
Encryption of sensitive fields
AES-256-GCM helper available for OAuth tokens and integration credentials.
A.10Implemented
Encryption in transit
TLS 1.2+ enforced on all public endpoints; HSTS enabled.
A.13A.14.1.2Documented
Backups
Scheduled workspace backups with retention and restore tooling.
A.12.3Implemented
Incident response + breach notification
Incident workflow with 72-hour notification helper for high-severity events.
A.16Implemented
Evidence exports for audits
CSV exports of audit log, DSAR log, consent ledger, login audit, and retention sweep history.
A.12.4Implemented
Change management
All entity changes logged via change log; release process documented.
A.12.1.2A.14.2Implemented
Logging and monitoring
Application logs, error events, and external log destinations.
A.12.4Implemented