Trust center
The answers a vendor review usually asks for, in one page — hosting, security posture, sub-processors, certification status, and data handling. It aggregates our security, data residency, and privacy pages, so you can review us without sending a questionnaire.
Last updated:
Hosting and data residency
- Customer data — databases, object storage, and secrets — is stored and processed in the EU (Frankfurt, Germany).
- A limited set of operational functions run in US cloud regions by design: the global content-delivery network and TLS certificate management, and inbound email routing.
- TLS protects data in transit; databases, object storage, and secrets use managed encryption at rest.
- There is no US or Asia-Pacific in-region hosting option today. Full detail, including current limits, is on the data residency page.
Security posture
- Deployments use short-lived, federated credentials — no static cloud keys.
- Access roles are scoped per service and environment, following least privilege.
- Admin access requires authenticated accounts and will require MFA for production operations.
- The full practice summary is on the security page.
Certifications — stated honestly
impersona.io is not yet SOC 2 or ISO 27001 certified — both certifications are on the roadmap. We would rather say that plainly than imply otherwise. Today the product maps to the threat-intelligence and monitoring controls in four common frameworks:
- ISO 27001:2022 A.5.7 — threat intelligence collection.
- NIST CSF 2.0 ID.RA-02 — cyber threat intelligence.
- SOC 2 CC7.2 — monitoring for anomalies indicative of malicious acts.
- NIS2 (EU) Article 21 — risk-management measures including external attack surface.
GDPR data-subject rights are built in for every user. Evidence packs, audit-log exports, and API access support compliance reporting wherever you operate.
Sub-processors
- EU-hosted cloud infrastructure, platform services and storage
- Stripe Ireland, billing and subscription metadata
- PostHog EU or self-hosted, analytics after opt-in only
- EU-hosted AI services, verdict synthesis
- WHOIS, RDAP, CT, and NRD data providers, domain enrichment
If a sub-processor ever requires a transfer outside the EEA, we document the transfer mechanism before relying on it.
Data handling and retention
- GDPR data-subject rights are built in for every user.
- Retention periods per data category are documented in the privacy policy.
- A Data Processing Addendum template is available: download DPA template.
Security questions and disclosure
Security questions and vulnerability reports go to security@impersona.io. The machine-readable disclosure policy is published at /.well-known/security.txt.