Sysevo

Security

GDPR compliant today. Certifications are next.

We'd rather tell you exactly what's true about how we handle your data — what we already meet, and what we're still working toward — than put a badge on the page that isn't backed by a real audit.

How your data is handled today

Encryption in transit and at rest

Every connection to Sysevo — the website, the API, and the portal — runs over TLS. Data at rest in our database is encrypted using our infrastructure provider's built-in encryption.

Tenant isolation & access control

Each account's data is isolated with row-level security (RLS) policies enforced at the database. Application code uses scoped, environment-held credentials; the elevated service key that bypasses RLS never runs in the browser and is never exposed to the client.

Authentication & session security

Sign-in and sessions are managed by our authentication provider with securely handled tokens and automatic refresh. Passwords are never stored by us in plain text, and access is scoped to your own tenant.

Payment data never touches our servers

Card details are collected and processed directly by our payment processor (Stripe). Sysevo never stores, transmits, or has access to raw card numbers — this keeps our own PCI DSS scope minimal by design.

Automated backups

Your data is backed up automatically on a regular schedule by our infrastructure provider, so it can be recovered in the event of a failure. We still recommend you export anything business-critical for your own records.

Vendor-managed infrastructure

We run on established cloud infrastructure rather than self-managed servers, so patching, network security, and DDoS mitigation for the underlying platform are handled by vendors whose full-time job is exactly that.

GDPR & UK GDPR — compliant today

This isn't a roadmap item. Sysevo is based in the UK and built these in from the start — full detail is in our Data Processing Agreement and Privacy Policy.

A real Data Processing Agreement

Available to every Business and Enterprise customer, covering our role as processor, sub-processor terms, and international transfer mechanisms — not a placeholder page.

Data subject rights, honoured on a deadline

Access, rectification, erasure, restriction, portability, objection, and consent withdrawal — all handled within one month, every time, not just on paper.

Documented sub-processors

We use a small set of established providers for hosting, payments, email, and voice AI. A full named list is available under a signed DPA, and customers get at least 30 days' notice before we add or replace one.

Lawful international transfers

Where a sub-processor operates outside the UK/EEA, we rely on appropriate safeguards — the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or the SCCs — with additional safeguards where needed.

Consent-gated analytics

Analytics cookies only load after you actively accept them in our cookie banner. Reject them and we simply don't load them — no dark patterns, no pre-ticked boxes.

Certifications — the honest roadmap

Unlike GDPR, these require a third-party audit. We're not certified for any of the below yet — here's exactly where things stand, so procurement doesn't have to guess.

Not yet certified

SOC 2 Type II

A Type II report requires 6–12 months of audited operating history. We're building toward this and will publish our report here the moment it's issued — not before.

Not yet available

HIPAA / signed BAA

We don't currently offer a Business Associate Agreement. If your use case involves protected health information, please talk to us before signing up — we'd rather tell you now than have you find out later.

Not yet certified

ISO 27001

Not pursued yet. If this is a hard requirement for your procurement process, get in touch — it helps us prioritise.

Found a security issue?

We don't have a formal bug bounty program yet. If you find a vulnerability, email us directly and we'll respond as a priority — we won't pursue legal action against good-faith, non-destructive security research.

security@sysevo.io

Also see: Privacy Policy · DPA · Terms