All compliance documents
- Version
- 1.0 · Effective 2026-08-11
- Owner
- security@depozza.eu
- Review cycle
- Annual
- Mapped controls
- SOC 2 CC3 · ISO 27001 cl. 6, A.5.7, A.5.9
Asset inventory
- Application code and deployment pipeline.
- Managed EU database holding accounts, listings, bookings, messages and audit logs.
- Object storage for listing photos and identity documents.
- Third-party services: payments, email delivery, identity verification, error monitoring.
Risk assessment
Risks are assessed on likelihood and impact, at least annually and whenever a significant feature or supplier is added. Each risk has an owner, a treatment decision (mitigate, accept, transfer, avoid) and a review date.
Principal risks currently tracked
- Unauthorised access to another user's personal data — mitigated by row-level security plus column-level revokes.
- Payment fraud or chargeback abuse — mitigated by Stripe verification, identity checks and dispute workflow.
- Supplier outage or supplier breach — mitigated by EU managed providers and by contract; residual risk is accepted.
- Key-person dependency in a small team — partially mitigated by managed infrastructure and documented procedures; residual risk is accepted.
Honest statement of maturity
Depozza operates these controls today but has not yet completed an independent audit or an external penetration test. Where a control is aspirational rather than in place, this programme says so instead of implying certification.
Questions about this document
security@depozza.euThis document states Depozza SAS's own policy. It is not a certification, an audit report or a legal guarantee.