This programme documents what we actually do — access control, retention, incident response, change management, continuity, risk and suppliers. It is written for auditors, insurers and business customers who need evidence rather than marketing.
Policy documents
- Information security policy
The top-level policy: what Depozza protects, who is accountable, and the rules everyone working on the platform follows.
SOC 2 CC1–CC2 · ISO 27001 cl. 5, A.5.1 - Access control policy
How identities, permissions and least privilege are enforced — in the product, in the database and for administrators.
SOC 2 CC6 · ISO 27001 A.5.15–A.5.18, A.8.2 - Data retention and deletion
What Depozza keeps, for how long, and how you exercise your access, portability and erasure rights.
GDPR art. 5(1)(e), 15, 17, 20 · ISO 27001 A.5.33–A.5.34 - Incident response and breach notification
How Depozza detects, classifies, contains and communicates security incidents — including the 72-hour regulator deadline.
SOC 2 CC7 · ISO 27001 A.5.24–A.5.28 · GDPR art. 33–34 - Change management and secure development
How changes reach production safely: review, automated checks, versioned database migrations and the ability to roll back.
SOC 2 CC8 · ISO 27001 A.8.25–A.8.32 - Backups, availability and continuity
How Depozza keeps the service available and how data is restored if something is lost.
SOC 2 A1 · ISO 27001 A.5.29–A.5.30, A.8.13 - Risk and asset management
How Depozza identifies what matters, what could go wrong, and what is being done about it.
SOC 2 CC3 · ISO 27001 cl. 6, A.5.7, A.5.9 - Subprocessors and supplier management
The third parties that process personal data on Depozza's behalf, what they do, and where the data sits.
GDPR art. 28, 44–49 · ISO 27001 A.5.19–A.5.22
Control overview
Mapped to SOC 2 Trust Services Criteria, ISO/IEC 27001:2022 Annex A and the GDPR.
- In place
Row-level security on every table, plus column-level revokes on sensitive fields
CC6 · A.5.15
- In place
Multi-factor authentication and leaked-password checking on accounts
CC6.1
- In place
Append-only audit log of administrative and sensitive actions
CC7.2 · A.8.15
- In place
Versioned database migrations and automated checks before release
CC8.1
- In place
Encrypted automated backups with point-in-time recovery, stored in the EU
A1.2 · A.8.13
- In place
Self-service data export and account deletion in Settings
GDPR 15/17/20
- In place
Documented incident response with 72-hour regulator notification
GDPR 33 · CC7.4
- In place
Published subprocessor list with EU hosting or standard contractual clauses
A.5.19
- Planned
Independent external penetration test
CC4.1
- Planned
Third-party audit and certification (not yet started)
SOC 2 / ISO 27001
No certification claimed
Depozza SAS is not SOC 2 attested and not ISO 27001 certified, and HIPAA does not apply because we process no health data. These documents are our own commitments; controls marked “planned” are not yet in place.