Where your data lives and who can reach it

Security work is sensitive. Here is how Hisland Comply is hosted, what we hand to other companies, and what we have not done yet.

One instance per customer

Each customer gets a separate application and database. There is no shared tenant table to leak across, and we can upgrade, restore or delete one customer without touching another.

Your company
  • Application
  • Database
  • File storage
  • Backups
  • yourco.[domain]
Another customer
  • Application
  • Database
  • File storage
  • Backups
Another customer
  • Application
  • Database
  • File storage
  • Backups
All instances run in [provider, data centre region, country], inside the EU.

Who processes what

The full list of sub-processors, with any change announced [30] days ahead, is on the sub-processors page.

WhatWhereProviderWhen
Application, database, filesEU, [country][hosting provider]Always
BackupsEU, [country][provider]Always
AI assistant modelParis, FranceScalewayOnly when your organisation switches it on
Email notifications[region][provider]When notifications are on
Feedback and Ask Hisland messages[region]Hisland, [inbox tool]When you send one

How we run it

Encryption

Traffic is encrypted in transit with TLS. Encryption at rest: [confirm with provider].

Backups and restore

Backups every [24 h], kept for [n] days. Restores tested [how often].

Who at Hisland has access

Named operations staff only, for support and maintenance. Consultants see your instance only when you have engaged them. [confirm access logging]

Updates

The platform is pinned to a tested upstream release and updated on a regular schedule, with security fixes applied sooner.

Open source

The platform and the Hisland layer are published under AGPL-3.0, so anyone can read the code that handles your data.

Our own security programme

[State honestly: e.g. "We run our own ISMS in Hisland Comply and are working toward ISO 27001." Do not claim certification until it is issued.]

Penetration testing

[Not yet done / date and scope of last test]

Reporting a vulnerability

Email [security@ address]. We reply within [n] working days.

Documents for your review

Want to go through a security questionnaire with us? Contact us