Trust Center

Security and compliance,
without the runaround.

Everything procurement, security, and legal teams need to evaluate Screeq — in one place. Last updated June 27, 2026.

14-day free trial · No credit card · Cancel anytime

Certifications & frameworks

Where we are on the roadmap.

We publish status, not aspirations. Items marked "in progress" have a budget, an owner, and a timeline.

GDPR (EU 2016/679)
Operational
Controls operating — DPA pre-signed

Processing of EU/EEA personal data on behalf of Customer Controllers.

UAE PDPL (Federal Decree-Law 45 of 2021)
Operational
Controls operating — UAE data residency available

Processing of personal data of UAE residents.

ISO/IEC 27001
In assessment
Stage 1 audit Q3 2026

Screeq SaaS platform, supporting cloud infrastructure, and corporate IT.

ISO/IEC 27701 (PIMS)
Documented
Documented — extends the ISMS

Privacy Information Management System on top of ISO 27001.

SOC 2 Type II
In assessment
Observation window opens Q4 2026

Security, Availability, Confidentiality, Processing Integrity and Privacy.

ISO 9001
Documented
Documented — QMS operating

Engineering, customer onboarding, success and support.

How we operate

Security practices.

Encryption

All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Database backups are encrypted with separately-managed keys.

Access control

Row-level security on every tenant-scoped table. Role-based access for staff with least-privilege defaults. Production access requires SSO + hardware MFA.

Audit logging

Every privileged action — admin overrides, exports, deletions — is recorded in an immutable audit log available to Customer admins.

Vulnerability management

Dependency scanning on every build. Annual third-party penetration test. Critical CVEs patched within 7 days; high within 30.

Incident response

24/7 on-call rotation. Customers notified within 72 hours of confirmed personal-data breach, per GDPR Art. 33.

Business continuity

Daily encrypted backups with 30-day retention. RPO 1 hour, RTO 4 hours. DR drills run quarterly.

Sub-processor registry

Every vendor that touches your data.

Required by GDPR Art. 28 and SOC 2. Customers on Enterprise plans receive 30 days' advance notice of any addition.

VendorPurposeDataRegion
Amazon Web Services (AWS)Primary cloud hosting and computeAll Customer Data at restEU (Ireland), US (N. Virginia), UAE (Dubai)Trust page
CloudflareCDN, DDoS mitigation, edge runtimeRequest metadata, cached static assetsGlobal edge networkTrust page
Google Cloud (Gemini API)AI scoring, transcription, summarisationCandidate answer text and audio (no training)EU / USTrust page
OpenAIAI scoring and assessment grading (zero-retention)Candidate answer text (no training)USTrust page
ResendTransactional email deliveryRecipient email, message metadataUS / EUTrust page
StripeSubscription billing and payment processingBilling contact, payment method (tokenised)US / EUTrust page
SupabaseManaged Postgres, authentication, object storageAll Customer Data at restEU (Frankfurt), US, AP regionsTrust page
TwilioSMS notifications and OTP deliveryRecipient phone number, message bodyGlobalTrust page
Legal documents

Data Processing Addendum.

Pre-signed by Screeq and ready for your countersignature. Includes the EU Standard Contractual Clauses (2021/914) and the UK International Data Transfer Addendum for cross-border transfers.

Also available on request
  • • SOC 2 readiness letter
  • • Penetration test executive summary
  • • SIG Lite / CAIQ questionnaire (pre-filled)
  • • Business continuity & DR plan summary
  • • Cyber insurance certificate
Email coffee@screeq.com →