How Fidify protects client data
- Independent penetration testCompleted
- ISO/IEC 27001:2022In progress
- SOC 2In progress
- Data protection officerdpo@fidify.se
Encryption, residency and isolation
Customer-side encryption
Sovereign data residency
Organization isolation
GDPR-aligned
Certifications & audits
Independent penetration test
Most recent test Q1 2026, third-party assessor
ISO/IEC 27001:2022
Audit in progress, targeting certification 2026
SOC 2
Type I in progress, targeting H2 2026
Controls overview
Encryption
Access control
Vulnerability management
Incident response
Backups & recovery
Change management
AI model choice
Data handling
Where data lives
EU customers are hosted in the EU today. Customers in the Middle East, Africa, or other regions can be hosted in a matching region on request. Once agreed, data never leaves that jurisdiction. Customer remains the data controller; Fidify is the processor.
Sub-processors
We publish the current sub-processor list and notify customers of changes in line with the DPA. All sub-processors meet ISO 27001 or equivalent.
Retention & deletion
Customers control retention. On termination, customer data is exported on request and deleted from active systems within the contracted window.
Personal data in logs
We avoid writing identifying personal data to application logs.
Documents
Data processing agreement
Our standard DPA, available for review and signature.
Technical & organisational measures (TOMs)
Full GDPR Article 32 control documentation.
Sub-processors
The current sub-processor list. Customers are notified of changes in line with the DPA.
Privacy policy
How we handle personal data across our services.