Your data stays in the European Union

Processed in Frankfurt and elsewhere in the EU, never transferred out, and secured the way we ask our customers to be. Everything on this page can be pointed at: a provider on our sub-processor list, a setting in the product. What we cannot show, we do not claim.

  • SupabaseGermany
  • VercelEU
  • Amazon Web ServicesFrankfurt
  • CloudflareEU edge
  • SentryEU
  • MollieEU

GitHub and Namecheap, in the United States, are suppliers, not sub-processors: they hold source code and a domain, never customer data.

Frankfurt

Delivering security and privacy you can check

The eight questions a reviewer asks first, with our answers. Each one points at something you can open.

Designed with your security needs in mind

Where your data lives, how little of it we keep, who can reach it, and how you can prove all of that to your own auditor.

Data minimization

We ask for the least a vendor allows, and keep the fact rather than the person.

  • Fly.io · Read-only org token
  • GitHub · Granular read scopes
  • Mollie · Read permissions only
  • AWS · Read-only role you create

Read-only wherever it exists

Granular read scopes, read-only tokens and read-only roles. Where a vendor offers only broader access, the connector page says so before you connect.

Facts, not people

A reading keeps the fact, not the names in it. Personal data is removed before anything is stored.

Anonymous error reports

Error reports carry no personal data. They tell us what broke, never who was there.

Data access and erasure

No passwords to leak, a role for every person, and a way to be forgotten that keeps the record intact.

  • Email codefirst factor
  • Passkeysecond factor once trusted
  • Authenticator appsecond factor, with recovery codes
  • Single sign-on, SAMLthe only way in for your domain
RoleRead evidenceChange thingsBilling and roles
Owneryesyesyes
Manageryesyesno
Vieweryesnono

Two-factor, enforceable

An Owner can require a second factor for everyone in the organisation, and any member can end all of their sessions at once.

Roles you compose

Owner, Manager and Viewer are presets. Compose your own from fine-grained permissions, and add separation-of-duties rules that the product enforces.

The auditor seat

An invited auditor is a Viewer: every finding, control and piece of evidence, and no way to change any of it.

Erasure that keeps the record

A person who asks to be forgotten is removed; the events they caused stay, attributed to no one. Leavers lose access the moment they are removed.

Accountability and compliance

The evidence log is the record your auditor reads, this site carries the protections a reviewer checks, and every change passes the same gates before release.

What an event looks like, as an example

  • 09:14:02readingaws · bucket "exports" · public access blocked
  • 09:14:02readinggoogle workspace · 2-step verification · 41 of 41 members
  • 09:15:40changepolicy "backups.daily" · threshold set to 24 hours · by an owner
  • 09:21:11readinggithub · branch protection on main · required reviews 1

What this site enforces in every browser

Encrypted connections only
Browsers are told to never reach sudory.com over an unencrypted connection, and keep that rule for a year.
Only our own code runs
A content security policy allows scripts, styles and connections from the sources we name and nothing else.
Cannot be framed
No other site can embed sudory.com, which closes the door on clickjacking.
No referrer leaks
Addresses of pages you visit here are not passed on to other sites.
No device access
Camera, microphone and location are switched off for the whole site.

Append-only

Every reading and every change is an event with its timestamp. Nothing is pruned or edited after the fact.

Zero-error policy

A warning in the build stops the release. An error in production is fixed or explicitly accepted the day it appears. Every change is tested and reviewed first, and no developer has access to production data.

Sudory on Sudory

We run our own controls in the product and scan our own domain daily. The readings are on our vendor profile.

Additional resources

Ten sub-processors that handle customer data, three suppliers that never do, and the documents a reviewer asks for.

Suppliers, no customer data

What we do not claim yet

No certificate yet. Sudory holds no ISO 27001 certificate or SOC 2 report today. We are preparing for certification the way we ask our customers to: the controls run in Sudory itself, the evidence collects every day, and the readings are on our profile for anyone to read. Nothing on this page is legal advice.

Found something?

contact@sudory.com

We answer within one business day.