Risk and asset management

How Depozza identifies what matters, what could go wrong, and what is being done about it.

All compliance documents
Version
1.0 · Effective 2026-08-11
Owner
security@depozza.eu
Review cycle
Annual
Mapped controls
SOC 2 CC3 · ISO 27001 cl. 6, A.5.7, A.5.9

Asset inventory

  • Application code and deployment pipeline.
  • Managed EU database holding accounts, listings, bookings, messages and audit logs.
  • Object storage for listing photos and identity documents.
  • Third-party services: payments, email delivery, identity verification, error monitoring.

Risk assessment

Risks are assessed on likelihood and impact, at least annually and whenever a significant feature or supplier is added. Each risk has an owner, a treatment decision (mitigate, accept, transfer, avoid) and a review date.

Principal risks currently tracked

  • Unauthorised access to another user's personal data — mitigated by row-level security plus column-level revokes.
  • Payment fraud or chargeback abuse — mitigated by Stripe verification, identity checks and dispute workflow.
  • Supplier outage or supplier breach — mitigated by EU managed providers and by contract; residual risk is accepted.
  • Key-person dependency in a small team — partially mitigated by managed infrastructure and documented procedures; residual risk is accepted.

Honest statement of maturity

Depozza operates these controls today but has not yet completed an independent audit or an external penetration test. Where a control is aspirational rather than in place, this programme says so instead of implying certification.

Questions about this document

security@depozza.eu

This document states Depozza SAS's own policy. It is not a certification, an audit report or a legal guarantee.