Harborline · Trust Centre

Security, privacy and compliance at Harborline

Everything your security review needs on one page: our current compliance posture, the subprocessors we rely on, how customer data is handled, and a private channel for reporting security issues.

Written for the people who fill in vendor questionnaires — procurement, security and legal. If something you need is missing, ask and we will add it.

  • SOC 2 Type IIReport available under NDA
  • GDPRDPA available
  • ISO 27001Certification in progress

Last reviewed: 3 August 2026

Compliance posture

Where we stand today, stated in words rather than badges. Each programme below is either audited, contractually covered or honestly marked as in progress — and the paperwork is available on request.

SOC 2 Type II

Report available under NDA

An independent auditor examines our security, availability and confidentiality controls every year. The current report covers the twelve months to March 2026. Request it through the disclosure form below or from your account manager — a mutual NDA applies.

GDPR

DPA available

We act as a processor for customer content. Our standard data processing agreement includes the EU Standard Contractual Clauses and the UK Addendum, and stays aligned with the subprocessor list on this page. Countersigned copies usually come back within two business days.

ISO 27001

Certification in progress

Our information security management system follows ISO 27001:2022 and the stage 1 audit is complete. We expect certification in the first half of 2027 and will publish the certificate number here once issued — until then we make no certification claim.

Subprocessors

Third parties that may process customer data on our behalf. We give customers thirty days' written notice before adding or replacing a subprocessor, with the right to object in the DPA.

Subprocessors
Subprocessor Purpose Region
Amazon Web Services Application hosting, storage and managed databases EU (Ireland), backups in EU (Frankfurt)
Cloudflare Content delivery, DNS and DDoS protection Global edge network
Postmark Transactional email delivery United States
Stripe Payment processing — cardholder data never touches our systems United States / EU
Datadog Infrastructure monitoring, logging and alerting EU (Germany)
Plain Customer support conversations EU (Ireland)

Last updated: 14 July 2026

How we handle customer data

The short version of our data-handling practices. The full detail lives in the DPA and the SOC 2 report — both available through the disclosure form below.

Encryption

Data in transit is protected with TLS 1.2 or newer; data at rest with AES-256. Keys live in a managed key management service, rotate automatically and are never stored alongside the data they protect.

Retention and deletion

Customer content is kept for as long as your contract runs. After termination we delete it from production within 30 days and from encrypted backups within 90 days — sooner on written request.

Access to your data

Production access is limited to a small on-call group behind single sign-on and hardware-key MFA, granted just-in-time and fully logged. Support engineers see customer content only with your written consent.

Report a security issue

Found a vulnerability, or have a security question your questionnaire does not cover? Use this private channel. We read every report and will not pursue good-faith research that respects user privacy and gives us reasonable time to respond.

What to expect

  • We acknowledge new reports within two business days.
  • We keep you updated while we investigate and fix.
  • We ask that you avoid accessing other customers' data and give us time to remediate before any public disclosure.

This form transmits nothing by itself — no mail service is connected to this page. Submitting prepares your report as an email to our security team, which you then send from your own mail client.

Used only to reply to you. Leave blank to report anonymously.

Steps to reproduce, affected URLs or a plain description — at least 20 characters. Please do not include real customer data.

Frequently asked questions

The questions vendor reviews ask most often. If yours is not here, send it through the disclosure form and we will answer — and usually add it.

Can we see your SOC 2 report?

Yes. The current SOC 2 Type II report is available under a mutual NDA — request it through the disclosure form on this page or from your account manager, and we will usually turn it around within two business days.

Will you sign our DPA, or do you have your own?

We offer a standard data processing agreement that includes the EU Standard Contractual Clauses and the UK Addendum, kept aligned with the subprocessor list published here. If your legal team needs changes, send the redline to the security address on this page.

Where is our data hosted?

Production runs on AWS in the EU (Ireland) region, with encrypted backups in EU (Frankfurt). Customer content stays in those regions; a small number of subprocessors listed above process limited data elsewhere, for example transactional email delivery in the United States.

How do you handle vulnerability reports?

Report privately through the disclosure form below or by email to the security address shown on this page. We acknowledge within two business days, keep you updated while we fix, and do not pursue good-faith researchers who respect user privacy and give us reasonable time to respond.

Do you support single sign-on?

Yes — SAML 2.0 single sign-on and SCIM provisioning are included on Business and Enterprise plans, with MFA enforcement available for members who sign in with a password.