Trust Center

Security and reliability, built in right from the very first version.

iComply governs other organisations' compliance — so our own security, privacy and resilience are held to the highest standard. Here's how we protect your data.

Safety posture

How your data is protected.

Encryption everywhere

Data is encrypted in transit (TLS 1.2+) and at rest using managed keys.

Authentication & SSO

JWT authentication, MFA and SSO / SCIM for enterprise identity.

Tenant isolation

Line-level security and strict segregation by organisation and tenant.

Immutable audit trails

Every relevant action is recorded in an immutable manner to ensure full auditability.

Backups & recovery

Daily backups with retention periods and tested recovery procedures.

Data residency in the EU

Data hosted in the EU, with GDPR compliance by design.

Compliance & certifications

We comply with the standards we implement.

Our journey towards formal certification — and, of course, iComply runs its own programme at iComply.

ISO 27001

Information security management.

SOC 2 Type II

Trust services criteria.

GDPR

Data protection in the EU.

ISO 42001

AI management system.

Subcontractors

Who we work with.

A transparent list of the data processors involved in the delivery of iComply. The full DPA and the register of data processors are available on request.

SubcontractorPurposeRegion
Cloud hostingApplication & database hostingEU
Storage of objectsStorage of evidence & filesEU
Email deliveryTransactional notificationsEU
AI providerAI Co-pilot (opt-in, tenant-specific)EU
Do you need our safety documentation?

Please request our DPA, register of subcontractors and security overview — we’ll send them to you.