SopiSafe
Security

Your data is safe. Here's exactly how

We don't take shortcuts on security. Your data is encrypted. We log who accesses it. We don't sell it. If something goes wrong, we tell you in 72 hours. Below is exactly what all of that means.
How we protect data

Encrypted, isolated, logged

AT REST
  • AES-256 encryption in the database
  • Separate encryption keys for backups โ€” a compromised backup gives you nothing without the key
  • Your data is logically isolated from every other customer's data
  • Every access attempt is logged with timestamp, user ID, and IP address
IN TRANSIT
  • TLS 1.3 for all connections, no downgrade allowed
  • All APIs require HTTPS โ€” plain HTTP is redirected
  • Certificate pinning in client apps
  • No unencrypted data moves between services
AT ACCESS
  • MFA mandatory for all users, no exceptions
  • Role-based access โ€” a CFO sees different data than an AP clerk
  • Sessions time out after 30 minutes of inactivity
  • Every action is logged. We can tell you exactly who looked at what, and when
ON DELETION
  • You own your data. You can delete on demand.
  • Automatic deletion 90 days after your subscription ends
  • Deletion is permanent โ€” overwritten on disk, not soft-deleted
  • We provide a compliance confirmation on request
Certifications

We meet the standards your compliance team needs

Compliant
GDPR

Full EU compliance. DPA available. Standard Contractual Clauses in place. No transfer to non-EU jurisdictions.

In progress
SOC 2 Type II

Third-party audit of security, availability, and confidentiality controls. Expected Q1 2027.

Target Q1 2027
ISO 27001

Information security management certification. Demonstrates systematic risk management.

Compliant
NIS2 (EU)

EU Network and Information Security Directive 2. Critical infrastructure security measures implemented.

EU only
Data residency

All customer data stored in GCP EU regions. No transfer to US, UK, or other jurisdictions.

72-hour notify
Incident SLA

Security incident detected โ†’ affected customers notified within 72 hours, per GDPR Article 33.

Data access

What we see. What we don't

We see what we need to find billing drift. Nothing more.
Invoice amounts and line itemsYesWe need this to match against your contract
Contract terms and agreed pricingYesThis is what we're comparing against
Supplier names and invoice datesYesFor pattern detection across invoice cycles
Your company nameYesFor audit trail and reporting
Customer names in invoicesNoWe don't need it.
Payment method or bank detailsNoWe never touch your payments side
Personal data of your employeesNoUnless it's directly linked to a billed seat โ€” and even then, minimal
Negotiation context or side notesNoNot in invoices or contract PDFs we process
Third-party risk

We're only as secure as our supply chain

Cloud infrastructure

GCP EU region. GCP holds SOC 2 and ISO 27001 โ€” we audit their reports annually. Shared responsibility model: they own the hardware, we own the application.

Third-party services

Email, analytics, monitoring vendors all have signed Data Integration Agreements. None of them can use your data for their own purposes.

Incident response

Breach detected: notification within 72 hours, forensic analysis, remediation plan, full compliance report per GDPR Article 33.

Annual security audits

Third-party security audit annually. Reports available to enterprise customers on request under NDA.

Questions

Security questions we get a lot

No. Data is encrypted. Access requires MFA, role-based permissions, and every access is logged. Engineers access production only to debug active issues โ€” never in bulk. All access is audited.

We notify you within 72 hours with specifics: what was accessed, by whom or what, and what we're doing about it. We carry cyber liability insurance. We've never had a breach, but we have a plan for it.

No. Not to advertisers, data brokers, or competitors. Your data is yours. If we shut down, it stays yours โ€” we'll export it or delete it, your choice.

No. We use AI assistance to help review findings. It does not train on customer data, and it never makes decisions on your behalf.

Yes. We provide a security brief, DPA. We complete vendor security questionnaires (Vanta, SecurityRAT, standard formats).

Documents

Agreements available on request

Data Processing Agreement

GDPR-compliant DPA with Standard Contractual Clauses. Customisable for enterprise.

Security brief

Overview of architecture, encryption, access controls, and incident response policy.

Compliance reports

SOC 2 / ISO 27001 reports available on request under NDA.

Vendor questionnaires

We complete Vanta, SecurityRAT, and standard industry questionnaire formats.

Need a specific doc, want to run a vendor assessment, or have a security question?

security@sopisafe.com โ†’

Your data, your control. Always

Curious about architecture, compliance, or anything specific? Our security team answers diligence questions directly.
See how it works