Skip to content

Trust center

The answers a vendor review usually asks for, in one page — hosting, security posture, sub-processors, certification status, and data handling. It aggregates our security, data residency, and privacy pages, so you can review us without sending a questionnaire.

Last updated:

Hosting and data residency

  • Customer data — databases, object storage, and secrets — is stored and processed in the EU (Frankfurt, Germany).
  • A limited set of operational functions run in US cloud regions by design: the global content-delivery network and TLS certificate management, and inbound email routing.
  • TLS protects data in transit; databases, object storage, and secrets use managed encryption at rest.
  • There is no US or Asia-Pacific in-region hosting option today. Full detail, including current limits, is on the data residency page.

Security posture

  • Deployments use short-lived, federated credentials — no static cloud keys.
  • Access roles are scoped per service and environment, following least privilege.
  • Admin access requires authenticated accounts and will require MFA for production operations.
  • The full practice summary is on the security page.

Certifications — stated honestly

impersona.io is not yet SOC 2 or ISO 27001 certified — both certifications are on the roadmap. We would rather say that plainly than imply otherwise. Today the product maps to the threat-intelligence and monitoring controls in four common frameworks:

  • ISO 27001:2022 A.5.7 — threat intelligence collection.
  • NIST CSF 2.0 ID.RA-02 — cyber threat intelligence.
  • SOC 2 CC7.2 — monitoring for anomalies indicative of malicious acts.
  • NIS2 (EU) Article 21 — risk-management measures including external attack surface.

GDPR data-subject rights are built in for every user. Evidence packs, audit-log exports, and API access support compliance reporting wherever you operate.

Sub-processors

  • EU-hosted cloud infrastructure, platform services and storage
  • Stripe Ireland, billing and subscription metadata
  • PostHog EU or self-hosted, analytics after opt-in only
  • EU-hosted AI services, verdict synthesis
  • WHOIS, RDAP, CT, and NRD data providers, domain enrichment

If a sub-processor ever requires a transfer outside the EEA, we document the transfer mechanism before relying on it.

Data handling and retention

  • GDPR data-subject rights are built in for every user.
  • Retention periods per data category are documented in the privacy policy.
  • A Data Processing Addendum template is available: download DPA template.

Security questions and disclosure

Security questions and vulnerability reports go to security@impersona.io. The machine-readable disclosure policy is published at /.well-known/security.txt.