DPPAutomate
NewBattery Regulation 2027 compliance pack is live.Read
DPPAutomate
Legal

Trust, by design. Audited by default.

Migrating to the EU, cryptographically signed, and built for regulators who actually look. Read the controls. Request the reports.

  • EU migration underway
  • Cryptographic signatures
  • GDPR-compliant
Certifications

What we have, what we are earning, what is next.

SOC 2 Type II

In progress

Independent audit of our security, availability, and confidentiality controls. Underway with our auditor.

ISO 27001

In progress

Information Security Management System aligned to ISO/IEC 27001. Stage 1 prep in progress.

TISAX

Roadmap

Automotive supply-chain assessment. Scoped for the next compliance cycle.

GDPR-compliant

Earned

EU migration underway, Article 28 DPA, SCCs Module Two, 30-day deletion windows. Compliant by default.

EU migration commitment

Earned

Customer data is processed and stored in Convex US East (N. Virginia) today, governed by the EU Standard Contractual Clauses; committed target region is Convex EU West (Ireland).

Annual penetration test

In progress

Third-party offensive security test of the production app. Summary available on request after each cycle.

Commitments

Four promises we make on every passport.

01 · Security

Defence at every layer.

Encryption in transit and at rest, encrypted service-to-service traffic, and a cryptographically signed audit trail for every passport event.

02 · Privacy

European data, European rules.

GDPR-compliant data handling, EU migration underway, and customer-managed encryption keys (BYOK) for Enterprise plans.

03 · Availability

Built to stay up.

Single-region on Convex US East today, migrating to Convex EU West (Ireland), with a real-time status page. A custom SLA is available on Enterprise.

04 · Transparency

No surprises, ever.

Public DPA and this Trust Center. Subprocessor changes notified 30 days ahead. Every incident published within five business days.

Architecture

The controls behind the claims.

Encryption in transit

TLS 1.2+ on every public endpoint. Encrypted, authenticated traffic between internal services.

Encryption at rest

AES-256 across databases, blob storage, and backups. Per-tenant keys with documented rotation.

Identity & access

Clerk-backed identity with role-based access. SSO and SCIM are on our roadmap for Enterprise plans.

Network isolation

Per-environment VPCs with no public database endpoints. Egress allowlisted, ingress filtered at the edge.

Audit logging

Cryptographically signed, append-only audit trail. Immutable revision history for every passport.

Customer-managed keys

Enterprise customers can BYOK (bring your own key) for at-rest encryption, rotated on your schedule.

Data residency

Your data, on a clear path to Europe.

Customer data is processed and stored in Convex US East (N. Virginia) today. No copies, replicas, or backups leave that deployment - not for analytics, not for support, not for failover.

Swiss-headquartered, migrating to EU-hosted: our committed target region is Convex EU West (Ireland). Cross-border transfers under GDPR Article 44+ are governed by the EU Standard Contractual Clauses (2021/914), Module Two, with our standard DPA.

Swiss HQ · EU migration underway
Current region
US East
United States

Current production region for compute, storage, and audit logs. Serves all customer traffic today.

Single-region
Target region
EU West
Ireland

Committed target region for full EU residency. Migration will be announced to all customers in advance.

Single-region
Reports & documents

Everything procurement and security teams ask for.

  • SOC 2 Type II report
    In progress
    Last updated
    In progress
    Request status
  • ISO 27001 certificate
    In progress
    Last updated
    In progress
    Request status
  • Penetration test summary
    Available on request
    Last updated
    NDA required
    Request
  • Subprocessor list
    Public
    Last updated
    Maintained continuously
    View on /dpa
  • Data Processing Agreement (DPA)
    Public
    Last updated
    May 2026
    View on /dpa
  • Privacy Policy
    Public
    Last updated
    May 2026
    View privacy
  • Architecture white paper
    Available on request
    Last updated
    NDA required
    Request

Reports tagged "In progress" are being prepared with our auditor. NDA-gated documents are sent within two business days of a written request from a named procurement or security contact.

Responsible disclosure

Find a vulnerability? Tell us first.

In scope: the production application, customer data, and our public APIs. Out of scope: third-party services we depend on (Clerk, Convex, Google) - report those to the vendor directly.

Email reports to the address below. PGP-encrypted submissions are welcome - request our public key in your first message.

We acknowledge every report within 72 hours, triage within five business days, and aim to ship a fix for critical findings within fourteen days.

Safe harbour: we will not pursue legal action against good-faith researchers who follow this policy and avoid privacy violations, service disruption, or data exfiltration.

info@dppautomate.comUse "security" in the subject line for fastest triage.
Hall of fame
Be the first.

No public disclosures to date. Researchers who report a valid issue will be acknowledged here, with consent.

Bug bounty · Roadmap
Incidents

Operational history, no spin.

Reportable incidents
0
Zero reportable incidents to date.

Counted from launch in 2024 through today. Every reportable incident is published within five business days.

All clear

How we publish incidents.

A reportable incident is any unplanned event that affects confidentiality, integrity, or availability of customer data. We publish a public post-mortem with root cause, customer impact, and remediation within five business days. Subscribe at the status page below.

status.dppautomate.com
Security contact

Reach the security team.

For vendor due-diligence, security questionnaires, or compliance escalations - write to the address below and our security lead will respond.

Security email
info@dppautomate.com

Use "security" in the subject line for fastest triage.

Operating entity
DPPAutomate
Schlosstalstrasse 202
8408 Winterthur
Switzerland