Product decisions come from compliance officers, ICT risk managers and procurement leads describing what they actually do on a Tuesday, not from a control framework. When those two disagree, the Tuesday wins, because a control nobody performs is not a control.
We are deliberately early in the way we say so. There is no pretence of a large team behind the product, no invented customer logos, and no case study written before a customer existed. Penetration testing is carried out by DossierSec, a specialist security firm under the same ownership as Relynt, which the security page says plainly rather than calling it independent. Where we do not yet hold a certification, the security page says nothing rather than implying one.
The same discipline runs through the software. Backups are restored and verified on a schedule rather than assumed to work. Every sub-processor that touches customer data is published, including the one that runs outside the EU and how to switch it off. The incident response process states the windows in which we would tell you something went wrong.
None of that is remarkable. It is simply the standard a regulated buyer applies to its own vendors, applied to us.