All compliance documents
- Version
- 1.0 · Effective 2026-08-11
- Owner
- security@depozza.eu
- Review cycle
- Annual
- Mapped controls
- SOC 2 A1 · ISO 27001 A.5.29–A.5.30, A.8.13
Hosting
The application and database run on managed EU infrastructure. Data is encrypted in transit with TLS and encrypted at rest by the hosting provider.
Backups
- The database is backed up automatically by the managed platform, with point-in-time recovery within the provider's retention window.
- Backups are encrypted and stored in the EU.
- Restores are only performed by the security owner, and any restore is recorded.
Availability
- The frontend is served from a global edge network with automatic failover between nodes.
- Errors and outages surface through centralised error capture.
- Payment processing depends on Stripe; if Stripe is unavailable, bookings can be created but payment is retried rather than lost.
Continuity assumptions
Depozza is a small team operating a managed stack. Our continuity plan relies on provider-level redundancy plus restorable backups rather than on self-operated failover clusters. This is stated plainly so reviewers can judge it.
Questions about this document
security@depozza.euThis document states Depozza SAS's own policy. It is not a certification, an audit report or a legal guarantee.