How SetTern.io protects your data and the data of the people you move. Sixteen audit-ready compliance docs ship with the product, the data inventory is short on purpose, and every architectural choice is explainable in a paragraph.
The boring controls everyone asks about. Modern defaults, documented configuration, no exotic crypto.
max-age=31536000 · includeSubDomains · preloadThe four entities that handle your data on our instructions and what they actually do. Updated quarterly. We notify customers in writing 30 days before adding a new sub-processor.
EU-only deployment is on the v2.0 roadmap for Programme-licence customers who need data residency guarantees beyond the multi-region default. Contact security@settern.io for early-access scoping.
One-click export, one-click erasure. Requests handled inside the in-app My Account screen — or by emailing privacy@settern.io. We respond within 30 days (typically same business day).
We keep what we need for as long as we need it. The defaults below are designed to support you mid-move and for a reasonable audit window after; per-tenant overrides are available for B2B contracts.
A written runbook, a single point of contact, and a 72-hour breach-notification commitment that matches our UK GDPR obligations.
Triggering events: unauthorised access to a customer record, sub-processor breach affecting our customer data, sustained service unavailability beyond our published SLA. The on-call engineer pages the incident commander within 15 minutes of confirmation.
Customer notification: if your data is affected, you receive a written notification within 72 hours of confirmation per UK GDPR Art. 33. The notification includes scope, root cause (where known), remediation, and a single-point-of-contact for follow-up questions.
Status page: live at status.settern.io. Subscribe by email or RSS for incident updates. We publish post-mortems for any incident lasting more than 30 minutes.
Dependencies, exposed surfaces, and how we respond when someone tells us something is wrong.
Dependency scanning: Dependabot + GitHub Advanced Security on every push. Critical vulnerabilities are patched within 24h, high within 7 days, medium within 30 days.
Coordinated disclosure: if you find a vulnerability, please email security@settern.io with steps to reproduce. We acknowledge within 48h, fix critical issues within 7 days, and credit you (with your permission) in our changelog. We don't run a public bug bounty today; we will scope one for v2.0.
Penetration testing: annual third-party pen test on the production environment. The latest report is available under NDA for Programme-licence customers from security@settern.io.