Trust & Security
Trust, security & compliance
How we protect your data and your customers' data. Below is exactly which standards Infaris meets today, and what's on the roadmap.
IMDigital · KvK 95452354 · Bennekom, the Netherlands
Infaris is IMDigital's identity and monitoring platform. Guard measures uptime, devices, synthetic checks and RUM. This page states, per topic, what is verifiable today and what is still on the roadmap. We do not hold an ISO 27001 or SOC 2 certificate.
Last verified 11 September 2026
Compliance
Green is verifiable today. Amber is a goal, not a certificate.
GDPR
ActiveProcessing under Regulation (EU) 2016/679 and the Dutch implementation act. The DPA is public.
ISO 27001
On the roadmapProcesses follow ISO/IEC 27001:2022. There is no certificate and no completed independent audit.
SOC 2 Type II
On the roadmapAn engagement covering security, availability and confidentiality is planned. There is no report.
PCI DSS
Via partnerCard payments run entirely through Stripe (PCI DSS Level 1). Infaris does not store card data.
Documents
Public documents, no login. Internal pentest or ISMS reports are deliberately not listed.
Web & email security
Encrypted traffic and authenticated email, measured on the live domain.
HTTPS / TLS
All traffic runs over a valid TLS certificate. Unencrypted connections are rejected.
HSTS Preload
Strict-Transport-Security with includeSubDomains and preload (2 years) forces HTTPS in every browser.
SPF, DKIM & DMARC
Email authentication against spoofing and phishing. DMARC is set to reject with strict alignment (adkim=s, aspf=s). MTA-STS is on enforce.
Security headers
X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy guard against clickjacking and data leakage.
Content Security Policy
A strict CSP restricts which scripts and resources may load, mitigating cross-site scripting (XSS).
DNSSEC
Our DNS records are cryptographically signed so they can't be tampered with in transit.
Cloudflare WAF & DDoS
A Web Application Firewall and DDoS mitigation filter malicious traffic before it reaches our platform.
Identity & access
Modern, phishing-resistant authentication for every account.
Multi-factor authentication
Protect accounts with a second factor on top of the password.
Passkeys / WebAuthn
Passwordless, phishing-resistant sign-in with biometrics or a hardware key.
OAuth 2.0 & OpenID Connect
Standards-based single sign-on with a public OpenID configuration and JWKS endpoint.
Bot protection
Cloudflare Turnstile blocks automated abuse without intrusive captchas.
Privacy & GDPR
Data protection under the European GDPR, by design.
GDPR compliant
Processing under the General Data Protection Regulation (EU) 2016/679 and the Dutch implementation act.
EU hosting
Data is stored and processed within the European Union (Netherlands).
Data Processing Agreement
A Data Processing Agreement (DPA) is available for business customers.
Right to access & erasure
Export or delete your data on request, in line with your rights under the GDPR.
Certifications
Independent audits we're pursuing. Honestly: these are not finished yet.
PCI DSS
Card payments are handled entirely by Stripe, a PCI DSS Level 1 certified provider. We never store card data ourselves.
ISO 27001
We're shaping our processes around the ISO 27001 information security standard, with certification as the goal.
SOC 2 Type II
A SOC 2 engagement covering security, availability and confidentiality is planned.
Sub-processors
Vendors that process personal data for Infaris services. The DPA confirms the customer-specific list before signing.
OVH
Netherlands / EUProduction hosting of the Infaris platform (self-hosted Docker).
Cloudflare
Edge, with EU processing where applicableDNS, WAF, DDoS mitigation, Turnstile and encrypted offsite backups (R2).
Stripe
EU entity for European customersSubscription and card payments. No card data in our systems.
FAQs
- Where is the data stored?
- Inside the European Union, in the Netherlands. Traffic runs over TLS. Unencrypted connections are refused.
- Are you ISO 27001 or SOC 2 certified?
- No. We shape processes around ISO 27001 and have SOC 2 planned. We do not hold those certificates today. What does apply is listed per standard above.
- Is there a data processing agreement?
- Yes. The model DPA is at infaris.com/dpa and can be used without asking us first. The definitive sub-processor list is confirmed before signing.
- How do I report a vulnerability?
- Email info@infaris.com. Responsible disclosure is welcome. There is no bug-bounty programme.
Have a security question or found a vulnerability?
We value responsible disclosure. Reach out to our security team and we'll respond quickly.
Email info@infaris.com