Trust

Trust & compliance

Everything your procurement reviewer needs, in one place — security posture, privacy, DPA, sub-processors, and live status.

Security posture

What's in place today

The controls we run, and the boundaries we deliberately keep out of scope.

  • GDPR support

    Available

    EU-hosted infrastructure, signable DPA, documented sub-processor list, 72-hour breach notification commitment.

  • TLS everywhere

    In place

    All connections encrypted in transit. Integration OAuth tokens encrypted at rest.

  • Breach notification

    Committed

    72-hour customer notification commitment in our DPA, with a documented incident response process.

  • Sub-processor transparency

    Published

    A live list of every third party that touches your data, with prior notice before adding or replacing any of them.

Status reviewed quarterly. If something above is out of date, email [email protected] and we'll fix it.

Sub-processors

Who processes your data

A short list, kept current. New sub-processors require customer notice under our DPA.

ProviderPurposeRegion
StripePayment processingUS (SCCs in place)
HetznerHosting & databaseEU
CloudflareEdge network, DDoS mitigationGlobal
PostmarkTransactional emailUS (SCCs in place)
PostHogProduct analyticsEU
SentryError trackingEU
Laravel NightwatchApplication monitoringUS (SCCs in place)

Need something a reviewer asked for?

Security questionnaire, counter-signed DPA, custom retention — ask.

Email [email protected]

Cookie preferences

Essential cookies keep Pokor working. Optional analytics and external widgets only load if you say yes. Privacy policy