Trust & Security

Trust, security & compliance

How we protect your data and your customers' data. Below is exactly which standards Infaris meets today, and what's on the roadmap.

IMDigital · KvK 95452354 · Bennekom, the Netherlands

Infaris is IMDigital's identity and monitoring platform. Guard measures uptime, devices, synthetic checks and RUM. This page states, per topic, what is verifiable today and what is still on the roadmap. We do not hold an ISO 27001 or SOC 2 certificate.

Last verified 11 September 2026

Compliance

Green is verifiable today. Amber is a goal, not a certificate.

GDPR

Active

Processing under Regulation (EU) 2016/679 and the Dutch implementation act. The DPA is public.

ISO 27001

On the roadmap

Processes follow ISO/IEC 27001:2022. There is no certificate and no completed independent audit.

SOC 2 Type II

On the roadmap

An engagement covering security, availability and confidentiality is planned. There is no report.

PCI DSS

Via partner

Card payments run entirely through Stripe (PCI DSS Level 1). Infaris does not store card data.

Documents

Public documents, no login. Internal pentest or ISMS reports are deliberately not listed.

Web & email security

Encrypted traffic and authenticated email, measured on the live domain.

Active

HTTPS / TLS

All traffic runs over a valid TLS certificate. Unencrypted connections are rejected.

Active

HSTS Preload

Strict-Transport-Security with includeSubDomains and preload (2 years) forces HTTPS in every browser.

Active

SPF, DKIM & DMARC

Email authentication against spoofing and phishing. DMARC is set to reject with strict alignment (adkim=s, aspf=s). MTA-STS is on enforce.

Active

Security headers

X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy guard against clickjacking and data leakage.

Active

Content Security Policy

A strict CSP restricts which scripts and resources may load, mitigating cross-site scripting (XSS).

Active

DNSSEC

Our DNS records are cryptographically signed so they can't be tampered with in transit.

Active

Cloudflare WAF & DDoS

A Web Application Firewall and DDoS mitigation filter malicious traffic before it reaches our platform.

Identity & access

Modern, phishing-resistant authentication for every account.

Active

Multi-factor authentication

Protect accounts with a second factor on top of the password.

Active

Passkeys / WebAuthn

Passwordless, phishing-resistant sign-in with biometrics or a hardware key.

Active

OAuth 2.0 & OpenID Connect

Standards-based single sign-on with a public OpenID configuration and JWKS endpoint.

Active

Bot protection

Cloudflare Turnstile blocks automated abuse without intrusive captchas.

Privacy & GDPR

Data protection under the European GDPR, by design.

Active

GDPR compliant

Processing under the General Data Protection Regulation (EU) 2016/679 and the Dutch implementation act.

Active

EU hosting

Data is stored and processed within the European Union (Netherlands).

Active

Data Processing Agreement

A Data Processing Agreement (DPA) is available for business customers.

Active

Right to access & erasure

Export or delete your data on request, in line with your rights under the GDPR.

Certifications

Independent audits we're pursuing. Honestly: these are not finished yet.

Via partner

PCI DSS

Card payments are handled entirely by Stripe, a PCI DSS Level 1 certified provider. We never store card data ourselves.

On the roadmap

ISO 27001

We're shaping our processes around the ISO 27001 information security standard, with certification as the goal.

On the roadmap

SOC 2 Type II

A SOC 2 engagement covering security, availability and confidentiality is planned.

Sub-processors

Vendors that process personal data for Infaris services. The DPA confirms the customer-specific list before signing.

OVH

Netherlands / EU

Production hosting of the Infaris platform (self-hosted Docker).

Cloudflare

Edge, with EU processing where applicable

DNS, WAF, DDoS mitigation, Turnstile and encrypted offsite backups (R2).

Stripe

EU entity for European customers

Subscription and card payments. No card data in our systems.

FAQs

Where is the data stored?
Inside the European Union, in the Netherlands. Traffic runs over TLS. Unencrypted connections are refused.
Are you ISO 27001 or SOC 2 certified?
No. We shape processes around ISO 27001 and have SOC 2 planned. We do not hold those certificates today. What does apply is listed per standard above.
Is there a data processing agreement?
Yes. The model DPA is at infaris.com/dpa and can be used without asking us first. The definitive sub-processor list is confirmed before signing.
How do I report a vulnerability?
Email [email protected]. Responsible disclosure is welcome. There is no bug-bounty programme.

Have a security question or found a vulnerability?

We value responsible disclosure. Reach out to our security team and we'll respond quickly.

Email [email protected]