Where your data lives and who can reach it
Security work is sensitive. Here is how Hisland Comply is hosted, what we hand to other companies, and what we have not done yet.
One instance per customer
Each customer gets a separate application and database. There is no shared tenant table to leak across, and we can upgrade, restore or delete one customer without touching another.
- Application
- Database
- File storage
- Backups
yourco.[domain]
- Application
- Database
- File storage
- Backups
- Application
- Database
- File storage
- Backups
Who processes what
The full list of sub-processors, with any change announced [30] days ahead, is on the sub-processors page.
| What | Where | Provider | When |
|---|---|---|---|
| Application, database, files | EU, [country] | [hosting provider] | Always |
| Backups | EU, [country] | [provider] | Always |
| AI assistant model | Paris, France | Scaleway | Only when your organisation switches it on |
| Email notifications | [region] | [provider] | When notifications are on |
| Feedback and Ask Hisland messages | [region] | Hisland, [inbox tool] | When you send one |
How we run it
Encryption
Traffic is encrypted in transit with TLS. Encryption at rest: [confirm with provider].
Backups and restore
Backups every [24 h], kept for [n] days. Restores tested [how often].
Who at Hisland has access
Named operations staff only, for support and maintenance. Consultants see your instance only when you have engaged them. [confirm access logging]
Updates
The platform is pinned to a tested upstream release and updated on a regular schedule, with security fixes applied sooner.
Open source
The platform and the Hisland layer are published under AGPL-3.0, so anyone can read the code that handles your data.
Our own security programme
[State honestly: e.g. "We run our own ISMS in Hisland Comply and are working toward ISO 27001." Do not claim certification until it is issued.]
Penetration testing
[Not yet done / date and scope of last test]
Reporting a vulnerability
Email [security@ address]. We reply within [n] working days.
Documents for your review
- Data processing agreementGDPR Article 28 terms
- Sub-processorsWho, where and why
- Security overviewPDF for questionnaires [later]
- Privacy noticeHow we handle personal data
Want to go through a security questionnaire with us? Contact us