Security and compliance, end to end
Security and compliance requests follow predictable patterns. A procurement team scoping a hosting contract asks much the same fifteen questions every time: data residency, encryption, backup retention, breach response, GDPR posture, accreditation status, subprocessor lists, business continuity and supplier risk. Most providers scatter the answers across a website or wait to be asked formally. We collected them in one place, because the second hardest part of a procurement is finding the documentation and the hardest is a supplier who cannot produce it.
Certifications and alignment we operate under: ISO 27001 certified upstream datacentre partners with certification documentation available on request, GDPR-compliant data processing arrangements with formal DPA documentation for customers who need it, EU data residency in named member states where required, and a Green Web Foundation verified hosting directory entry. We do not claim certifications we do not hold, and this page is deliberately specific about which level of evidence applies to each item.
Operational practices as standard: TLS 1.2 or higher on every customer-facing endpoint, encryption at rest on backup storage, web application firewall management across all GreenStack tiers with custom rule writing available, documented incident response with defined escalation paths, structured backup retention with 30-day point-in-time recovery, immutable backup copies for ransomware resistance, a maintained subprocessor list provided under DPA, independent third-party penetration testing with remediation documentation, and quarterly review of access controls with privileged access management.
Documentation available before signature: a data processing agreement template, the named subprocessor list with locations and roles, business continuity and disaster recovery statements, a security policy summary, an environmental policy statement, named technical contacts, and a breach response procedure summary. Tell us at scoping which framework or questionnaire you are working to and we will assemble the right pack rather than sending a generic one.
The reviews are about the same things, over and over:
speed of response, depth of expertise, and named engineers who know the platform.
What Our Customers Say:
Let's Talk
Tell us which compliance framework or audit you're working to, what documentation you'll need from us, and roughly when. We'll come back with the right pack and a scoping conversation. No obligation, no automated funnel.