Snapshot 25897
Normalized text
Scripts and page chrome removed; this is what change detection compares.
SuperOffice Compliance Trust Center Trust is built over time. And when it comes to your data, trust is non-negotiable. At SuperOffice, security, privacy, and compliance are built into how we design, develop, and run our products, not added later. That means your data is safe, your privacy is protected, and our products and services comply with applicable laws, regulations, and recognised standards. This trust centre gives you a transparent view of how we work with security, privacy, and compliance across all our cloud products and services, and what that means for you as a customer. We follow European Union legal requirements and applicable local legislation, and we support this with clear governance, internal policies, and shared responsibility across the organisation. Everyone at SuperOffice plays a part in keeping customer data safe. Because protecting relationships also means protecting the data behind them. See our resources and agreements Compliance SuperOffice operates in line with recognised certifications and regulatory frameworks. ISO 27001 SuperOffice ISO / IEC 27001 Certificate. Date 18th of December 2025 SOC 2 Type 2 This audited attestation verifies that SuperOffice has proper controls within Security, Confidentiality and Privacy GDPR SuperOffice is GDPR compliant, and the SuperOffice software is ready to support your company to follow the regulation. EU DORA SuperOffice supports customers that operate under the EU DORA requirements CSRD The Corporate Sustainability Reporting Directive report shows how SuperOffice handles sustainability SOC 3 High level audit report for Security, Confidentiality and Privacy in SuperOffice Monitoring Continuously monitored by Secureframe View all Subprocessors This is an overview of the suppliers and sub processors for CRM Online. Visma IT & Communications AS Hosting Provider. Hosting and operations of all servers, and infrastructure for SuperOffice CRM Online. Data location: EU/ EULA (Norway) Microsoft Hosting Provider. Hosting and operations of servers, and infrastructure for SuperOffice CRM Online and operations. Identity provider and AI services Data location: EU/EULA Mailgun Mail services for sending and receiving emails in the SuperOffice application Data location: EU Amplitude Amplitude is used to monitor user behaviour in our product. Used by product team to improve our products. Data location: EU Userflow training Training and education for users in the SuperOffice application. Data location: EU App Store partners: Below is app store partners listed, which are included in the SuperOffice price list. They will need a special subscription or amendment to use. Infobridge Calendar synchronisation Service between SuperOffice CRM and various calendering Systems Data location: EU/EULA I-Centrum AB I-Centrum is a SuperOffice company offering integrations and tools to empower your business, Data location: EU/EULA Lyyti Lyyti is a SuperOffice company offering an all in one event platform integrated with SuperOffice Data location: EU/EULA View all Resources SuperOffice CRM Online Subscription Agreement (MSA) This is the standard Subscription agreement for all customers. ISO 27001 Certificate ISO 27001:2023 Certification ISO 27001 Statement of Applicability Statement of applicability. Date 08.12.2025 SuperOffice - SOC 2 Type II - 2025 A SOC 2 Type II report verifies that an organization not only has proper security controls (as in Type ), but that those controls actually operated effectively throughout the audit period. Pentest SuperOffice Q2 2026 Executive report perfom by Telenor CyberDefence Data Processing Agreement (DPA) This Data Processing Agreement governs the Processor’s rights and obligations, in order to ensure that all Processing of Personal Data is conducted in compliance with applicable data protection legislation. List of Data Processors, detailed This is the complete list of Subprocessors for SuperOffice , as listed above, but with more details. Consulting Subscription Terms These Consulting Subscription Terms apply to all recurring and subscription-based consulting offerings delivered by SuperOffice to the Customer DORA Addendum DORA Addendum can be signed by customer and SuperOffice when required DORA Cross reference table DORA Article 30 – Table of cross references to SuperOffice agreements View all FAQs More information about SuperOffice and Trust. How do you ensure the quality and security of application of app store partners and software? SuperOffice App Store Quality Assurance All applications available on the SuperOffice App Store are tested and certified for quality, security and SuperOffice CRM API Compliance. The tests cover the following areas: SuperOffice CRM Authentication Policies and Compliance SuperOffice API Compliance Performance tests Load and balancing Security All third-party applications have access to customer data through the SuperOffice APIs. SuperOffice has signed a Sub Data Processing Agreement with each of the App Store partners to secure their handling of data. In addition, App Store partners must sign a Data Processing Agreement (DPA) directly with the customer as part of their agreement. What is the SOC 2 type II and SOC 3 attestation SuperOffice holds? SOC 2 stands for System and Organisation Controls, and is a framework developed by the American Institute of CPA´s (AICPA) to ensure that software providers have good routines for handling customer data. The attestation covers Security, Confidentiality, and Privacy. The SOC 2 Type II is audited over time, and is an enhanced evaluation that the controls are in place. The SOC 3 attestation is a report that can be distributed freely. The SOC2 TypeII is only distributed to customers and customers after signing an NDA (non-disclosure agreement) How can I get status on SuperOffice Online maintenance or system status? SuperOffice notifies at least 24 hours in advance about all scheduled outage. System status and any scheduled downtime are presented at the login screen of each user and on the status page: status.superoffice.com. Service capacities and performance are continuously monitored. This way we can easily foresee the need for server and infrastructure upgrades. Our upgrade and patch management policy (schedule) is set to minimize operational impact on the customers. Patches of the system-critical issues are done as soon as possible. What is the Service availability for SuperOffice Online? SuperOffice has the goal of keeping its services up and running on a “24x7x365” basis. However, system maintenance might lead to short periods of unavailability. System maintenance is performed on a regular basis to provide our customers with the best performance, security and stability. Our maintenance schedule aims at minimizing disruption to normal business hours’ operation. Check https://status.superoffice.com for details Encryption of SuperOffice services All communication between our servers and the clients accessing our site is encrypted using Secure Socket Layer (SSL). All communication between SuperOffice mobile applications and the servers are also encrypted using SSL. We are always using internationally recognized cryptographic methods to protect information stored on our site, such as TLS and IPSEC/RSA256(SHA256withRSA)/HSTS. NIS2 and SuperOffice SuperOffice and NIS2 Compliance There is no formal NIS2 certification for cloud service providers — NIS2 is a regulatory directive that places obligations on the organizations operating within critical sectors, not on their suppliers. SuperOffice supports customers in meeting those obligations through our existing security framework. SuperOffice is certified under ISO 27001 and holds a SOC 2 Type II attestation, both of which substantially overlap with the security requirements of NIS2, covering risk management, access control, incident management, and business continuity. As your service provider, SuperOffice supports your NIS2 compliance through: Incident notification aligned with NIS2 reporting timelines Vendor documentation for your supply chain risk management obligations Sub-processor transparency via our maintained sub-processor list Security questionnaires and due diligence support on request Backup of SuperOffice All data is backed up every night and stored in two separate secure environments. Backup sets are encrypted and transmitted over an encrypted VPN tunnel. SuperOffice CRM is based on two types of data storage: Microsoft SQL Server Database and the Document Archive. All data is completely separated for each customer. All databases have a 30 days “point in time” backup. This means that a restore can be made from any specific date/time within the last 30 days. In addition, a monthly backup is performed and stored for 12 months. A yearly backup is stored for 5 years. All document archives have continuous mirroring between two physically separated data centers and have individual backups in both locations. The backup runs once a day (usually at night). Document changes are backed up and stored for 30 days. Backup of deleted files (documents) are stored for 90 days. Backup routines for third-party apps are subject to specifications and terms of service of the third-party app vendors and is not part of the SuperOffice CRM service scope. How do SuperOffice use AI training data? SuperOffice leverages AI to improve the core product experience and provide real value to our users in their day-to-day work. We strive to do this in a way that’s trustworthy, reliable, and user-centric. Your data is yours. Our AI Subprocessors are prohibited from using Customer Data to train models. The controls and permissions with respect to access and use of customer data will be respected, and is in the design isolated to each customer. Change log for the SuperOffice Trust Center 15th of July 2026: Lyyti OY (a SuperOffice company) added as an optional subprocessor. 30th of February 2026: SOC2 Type II report added. 18th of December 2025: SuperOffice ISO 27001 certificate and SOA updated. 9th of December 2025: Userflow Subprocessor, all services for SuperOffice customers are moved to Europe. 1st of November 2025: Updated to new Trust centre, moved information from Website Contact, questions or perform a security review Send your questions to: [email protected] Custom section title Custom section description Monitoring Confidentiality Data Retention and Disposal Policy A Data Retention and Disposal Policy specifies how customer data is to be retained and disposed of based on compliance requirements and contractual obligations. Retention of Customer Data Procedures are in place to retain customer data based on agreed-upon customer requirements or in line with information security policies. Disposal of Customer Data Upon customer request, Company requires that data that is no longer needed from databases and other file stores is removed in accordance with agreed-upon customer requirements. Data Classification Policy A Data Classification Policy details the security and handling protocols for sensitive data. Availability Business Continuity and Disaster Recovery Policy Business Continuity and Disaster Recovery Policy governs required processes for restoring the service or supporting infrastructure after suffering a disaster or disruption. Backup Restoration Testing Backed-up data is restored to a non-production environment at least annually to validate the integrity of backups. Uptime and Availability Monitoring System tools monitors for uptime and availability based on predetermined criteria. Physical Security Physical Security Safeguards Physical protections are in place to safeguard facilities, infrastructure, systems, and data from external and internal threats Physical Access Restrictions Processes are in place to create, modify or remove physical access to facilities such as data centers, office spaces, and work areas based on the needs of such individual. Physical Security Policy A Physical Security Policy that details physical security requirements for the company facilities is in place. Visitor Control Production facilities require all visitors to formally sign-in, unless preauthorization for the visitor exists. Physical Access Reviews Processes are in place to periodically review physical access to ensure consistency with job responsibilities. Customer data is stored and processed within EU/EULA Member States maintain conditions and limitations, with regard to the processing of genetic data, biometric data or data concerning health. Risk Assessment Vendor Risk Assessment New vendors are assessed in accordance with the Vendor Risk Management Policy prior to engaging with the vendor. Reassessment occurs at least annually. Risk Assessment Formal risk assessments are performed, which includes the identification of relevant internal and external threats related to security, availability, confidentiality, and fraud, and an analysis of risks associated with those threats. Vendor Due Diligence Review Vendor SOC 2 reports (or equivalent) are collected and reviewed on at least an annual basis. Risk Register A risk register is maintained, which records the risk mitigation strategies for identified risks, and the development or modification of controls consistent with the risk mitigation strategy. Vendor Risk Management Policy A Vendor Risk Management Policy defines a framework for the onboarding and management of the vendor relationship lifecycle. Risk Assessment and Treatment Policy A Risk Assessment and Treatment Policy governs the process for conducting risk assessments to account for threats, vulnerabilities, likelihood, and impact with respect to assets, team members, customers, vendors, suppliers, and partners. Risk tolerance and strategies are also defined in the policy. Communications Privacy Policy A Privacy Policy to both external users and internal personnel. This policy details the company's privacy commitments. Description of Services Descriptions of the company's services and systems are available to both internal personnel and external users. Confidential Reporting Channel A confidential reporting channel is made available to internal personnel and external parties to report security and other identified concerns. Communication of Security Commitments Security commitments and expectations are communicated to both internal personnel and external users via the company's website. Communication of Critical Information Critical information is communicated to external parties, as applicable. Terms of Service Terms of Service or the equivalent are published or shared to external users. Network Security Automated Alerting for Security Events Alerting software is used to notify impacted teams of potential security events. Network Traffic Monitoring Security tools are implemented to provide monitoring of network traffic to the production environment. Network Security Policy A Network Security Policy identifies the requirements for protecting information and systems within and across networks. Access Security Encryption and Key Management Policy An Encryption and Key Management Policy supports the secure encryption and decryption of app secrets, and governs the use of cryptographic controls. Least Privilege in Use Users are provisioned access to systems based on principle of least privilege. User Access Reviews System owners conduct scheduled user access reviews of production servers, databases, and applications to validate internal user access is commensurate with job responsibilities. Administrative Access is Restricted Administrative access to production infrastructure is restricted based on the principle of least privilege. Encryption-in-Transit Service data transmitted over the internet is encrypted-in-transit. Access Control and Termination Policy An Access Control and Termination Policy governs authentication and access to applicable systems, data, and networks. Asset Inventory A list of system assets, components, and respective owners are maintained and reviewed at least annually Removal of Access Upon termination or when internal personnel no longer require access, system access is removed, as applicable. Unique Access IDs Personnel are assigned unique IDs to access sensitive systems, networks, and information Incident Response Incident Response Plan Testing The Incident Response Plan is periodically tested via tabletop exercises or equivalents. When necessary, Management makes changes to the Incident Response Plan based on the test results. Incident Response Plan An Incident Response Plan outlines the process of identifying, prioritizing, communicating, assigning and tracking confirmed incidents through to resolution. Lessons Learned After any identified security incident has been resolved, management provides a "Lessons Learned" document to the team in order to continually improve security and operations. Tracking a Security Incident Identified incidents are documented, tracked, and analyzed according to the Incident Response Plan. 24/7 Security Operation Centre (SOC) in place Critical security incidents are addressed, and a defined notification process is followed. Change Management Secure Development Policy A Secure Development Policy defines the requirements for secure software and system development and maintenance. Change Management Policy A Change Management Policy governs the documenting, tracking, testing, and approving of system, network, security, and infrastructure changes. Baseline Configurations Baseline configurations and codebases for production infrastructure, systems, and applications are securely managed. Configuration and Asset Management Policy A Configuration and Asset Management Policy governs configurations for new sensitive systems Segregation of Environments Development, staging, and production environments are segregated. Production Data Use is Restricted Production data is not used in the development and testing environments, unless required for debugging customer issues. Vulnerability Management Vulnerability and Patch Management Policy A Vulnerability Management and Patch Management Policy outlines the processes to efficiently respond to identified vulnerabilities. Third-Party Penetration test performed at least 3 times a year A 3rd party is engaged to conduct a network and application penetration test of the production environment at least annually. Critical and high-risk findings are tracked through resolution. 24/7 Security Operation Centre Critical security incidents are addressed throughout the incident lifecycle. Organizational Management Background Checks Background checks or their equivalent are performed before or promptly after a new hires start date, as permitted by local laws. Disciplinary Action Personnel who violate information security policies are subject to disciplinary action and such disciplinary action is clearly documented in one or more policies. Acceptable Use Policy An Acceptable Use Policy defines standards for appropriate and secure use of company hardware and electronic systems including storage media, communication tools and internet access. Code of Conduct A Code of Conduct outlines ethical expectations, behavior standards, and ramifications of noncompliance. Roles and Responsibilities Information security roles and responsibilities are outlined for personnel responsible for the security, availability, and confidentiality of the system. Internal Control Monitoring A continuous monitoring solution monitors internal controls used in the achievement of service commitments and system requirements. Security Awareness Training Internal personnel complete annual training programs for information security to help them understand their obligations and responsibilities related to security. New Hire Screening Hiring managers screen new hires or internal transfers to assess their qualifications, experience, and competency to fulfill their responsibilities. New hires sign confidentiality agreements or equivalents upon hire. Information Security Policy An Information Security Policy establishes the security requirements for maintaining the security, confidentiality, integrity, and availability of applications, systems, infrastructure, and data. Internal Control Policy An Internal Control Policy identifies how a system of controls should be maintained to safeguard assets, promote operational efficiency, and encourage adherence to prescribed managerial policies. Performance Review Policy A Performance Review Policy provides personnel context and transparency into their performance and career development processes. Information Security Program Review Management is responsible for the design, implementation, and management of the organization’s security policies and procedures. The policies and procedures are reviewed by management at least annually. Independent Advisor The board of directors or equivalent entity function includes senior management and external advisors, who are independent from the company's operations. An information security team has also been established to govern cybersecurity. Performance Reviews Internal personnel are evaluated via a formal performance review at least annually Organizational Chart Management maintains a formal organizational chart to clearly identify positions of authority and the lines of communication, and publishes the organizational chart to internal personnel. Cybersecurity Insurance Cybersecurity insurance has been procured to help minimize the financial impact of cybersecurity loss events.