2026 Q4
VERBİS obligation assessment and registration
Assessing the registration obligation, data inventory and registration if required
%55
Trust Center
You trust us with accounting, payroll, customer and employee records. This center describes our infrastructure, tenant isolation, backups, subprocessors and certification roadmap without marketing gloss, keeping what is in place today separate from what is a target.
Contact usThe platform runs on a Kubernetes cluster we operate ourselves in a data center in Germany, behind Cloudflare. Row-level security is enabled in the database and blocks anonymous reads of personal data. Separation between companies is enforced mainly in the application layer, by the company filter on every query, together with role-based permissions.
We do not hold a certificate for any of the standards below today. They are roadmap items; the percentage shows the estimated progress of preparation work. Details are on the compliance page.
2026 Q4
Assessing the registration obligation, data inventory and registration if required
%55
2027 Q2
Information security management system, roadmap
%35
2027 Q3
Privacy information management on top of 27001, roadmap
%20
2027 Q4
Independent audit after an observation period, roadmap
%10
Infrastructure, tenant isolation, encryption, access control and audit trail.
Controller and processor roles, data categories per module and retention.
Data subject rights, how to apply, cross-border transfer and AI processing.
Roadmap for ISO, SOC 2, VERBİS and the AI Act; target quarter and preparation status.
A 6-hour database backup target, RPO and RTO targets, data export.
Service providers, their purpose, the data they process and location; 30-day notice.
Target 99.9% availability, maintenance windows, incident communication and support times.
Vulnerability reporting: scope, rules, safe harbor and response time targets.
The platform and database run in a data center in Germany. Personal data sent from Türkiye to Germany is a cross-border transfer under KVKK Article 9, and we are carrying out the process of signing the Board's standard contracts with recipients and notifying the Authority under Article 9(4)(c). See the KVKK and GDPR page for details.
No. We hold no certificate for these standards today. ISO/IEC 27001, 27701, 42001, ISO 9001 and SOC 2 Type II are on our roadmap; target quarters and preparation status are published on the compliance page.
Yes. As a tenant you are the data controller and we are your processor. We sign a data processing agreement on request; send your request through the contact page.
Follow the steps on the responsible disclosure page and report through the contact page. We do not pursue legal action against good-faith researchers.
Infrastructure, tenant isolation, encryption, access control and audit trail.
Data subject rights, how to apply, cross-border transfer and AI processing.
Service providers, their purpose, the data they process and location; 30-day notice.
Roadmap for ISO, SOC 2, VERBİS and the AI Act; target quarter and preparation status.
A 6-hour database backup target, RPO and RTO targets, data export.
Target 99.9% availability, maintenance windows, incident communication and support times.
Write to us about your procurement review, security questionnaire or data processing agreement request.
Contact us