Trust Center

We hold ourselves to the standard we set for you.

A sovereignty advisor that runs on US infrastructure has no business advising anyone. Here's how we protect your data — and how we keep our own house sovereign.

01Standards

What we claim is what we hold.

The principles we operate to today. Certifications will be listed here when they're earned — not before. That's the standard we'd hold any supplier to.

GDPRUK & EU-basedIndependent
02How we protect data

Security practices, in plain terms.

Encryption everywhere

Data encrypted in transit (TLS 1.3) and at rest. Customer-managed keys available on the platform.

Least-privilege access

Role-based access control, SSO and audit logging across all internal systems.

Data minimisation

We collect only what an engagement needs, and delete on request. Assessments run in your browser.

EU/UK residency by default

Your data is stored and processed within the EU/EEA and UK — never moved to a US region.

Sub-processor transparency

A published, EU-domiciled sub-processor list. We change it openly, with notice.

Tested resilience

Documented exit and recovery plans for every critical provider in our own stack.

03Sub-processors

Every one of our own suppliers is European.

We publish our sub-processors and keep them EU-domiciled by design. It's the clearest proof we can offer that the advice is real.

ProviderPurposeLocation
IONOSWebsite hosting & deploymentDEGermany (EU)
IONOSEmail & form deliveryGBUnited Kingdom
04Data residency commitment

“Your data is stored and processed within the EU/EEA and UK. We will never silently move it to a US region, and we self-host our own software — down to the fonts on this page.”

SovereignStack · data-residency policy

Due diligence

Need our DPA, security pack or sub-processor notices?

Tell us what your procurement or security team needs and we'll send it over.