Trust Center

Security, privacy, and compliance are built into how we operate. Use this page to understand how we protect your data and the infrastructure we run on.

Last reviewed: June 2026

Compliance

TechnologyChecker.io is independently certified across the standards that matter for handling your data.

GDPRGDPR
HIPAAHIPAA
SOC 2SOC 2
KVKKKVKK

SOC 2 audited · GDPR, HIPAA & KVKK compliant. We also align with California's CCPA, and build on SOC 2 / ISO 27001-certified infrastructure (AWS, Vercel, Cloudflare); payments are handled by Stripe, a PCI DSS Level 1 provider.

At a glance

Cloud hosting
AWS · Vercel · Cloudflare
Encryption
TLS 1.2+ in transit · AES-256 at rest
Access
MFA + role-based access control
Data we hold
Public web data

Public website content & technology signals, business contact data (names, emails, addresses), and intent signals derived by analyzing public web content with AI.

Documents & resources

Compliance reports, agreements, and security documentation. Public documents link directly; the rest are available on request — email us and we'll share them, under NDA where noted.

Security controls

Reviewed June 2026

The technical and organizational measures we use to protect your data, organized by area. Select a card to see the full detail.

Compliance & Privacy

  • SOC 2 audited
  • HIPAA compliant
  • GDPR, KVKK & CCPA aligned

Data Security

  • TLS 1.2+ encryption in transit
  • AES-256 encryption at rest
  • Encrypted, automated backups

Access Control

  • Role-based access control (RBAC)
  • Multi-factor authentication for admin access
  • Principle of least privilege

Infrastructure

  • AWS — compute & data storage
  • Vercel — application hosting & edge
  • Cloudflare — DNS & global CDN

Network Security

  • Cloudflare Web Application Firewall
  • Anti-DDoS protection & bot mitigation
  • HTTPS enforced across all surfaces

Application Security

  • Regular penetration testing
  • Vulnerability scanning
  • Secure code review

Payment Security

  • Stripe — PCI DSS Level 1 certified
  • No card numbers stored on our servers
  • Tokenized transactions

Monitoring & Logging

  • Audit logging
  • Access monitoring
  • Uptime & availability monitoring

Incident Response

  • Documented incident response plan
  • 72-hour breach notification (GDPR)
  • Dedicated security contact

People & Awareness

  • Security awareness training
  • Confidentiality agreements
  • Background checks for staff

Data Privacy & Your Rights

  • Access, rectification & erasure
  • Data portability (CSV / JSON)
  • Cookie consent management

Vendor & Subprocessor Management

  • Vetted, contractually-bound subprocessors
  • Standard Contractual Clauses (SCCs)
  • Subprocessor list maintained below

Subprocessors & infrastructure

We use the following trusted third parties to operate our service. All are bound by data processing agreements.

ProviderPurposeData regionCertifications
Amazon Web Services (AWS)Cloud compute & primary data storageEU / US regionsSOC 2 Type II, ISO 27001, PCI DSS
VercelApplication hosting & edge networkGlobal edgeSOC 2 Type II
CloudflareDNS, CDN, WAF & DDoS protectionGlobal edgeSOC 2 Type II, ISO 27001
StripePayment processing & billingUS / EUPCI DSS Level 1
PostHogProduct analyticsEU / USSOC 2 Type II
IntercomCustomer support & in-app messagingUSSOC 2 Type II

Have a security question?

Report a vulnerability, request our security documentation, or ask about our data practices. We respond to security reports as a priority.