Third Party Index

Snapshot 29790

Document
Trust center
URL
https://trust.staffbase.com/
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
browser
Size
80554 bytes
SHA-256 (raw)
e5a3d11cec8f7dadaf93548e326194e45bfb44626677c79583702fecd261683c
SHA-256 (normalized text)
ccb59aa07698cb67db40332023cdbf99e8ab0b15839fa3dba61fe531f375bbe6

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Announcements
2026 UK Cyber Essentials Certification achieved!
Published on Mar 23, 2026
Strengthening Our Security Posture: Staffbase Achieves UK Cyber Essentials CertificationWe’re excited to share another milestone in our security journey. Staffbase has successfully achieved the UK Cyber Essentials certification, reinforcing our commitment to maintaining strong security controls and protecting our customers’ data.
You can find more details about this certification in the “Security Certifications” section of our Trust Center.
Security Certifications
Documentation of our compliance against global standards including certifications, attestations, and audit reports.
Documents & Reports
Security, Legal, Finance and Business documents.
Company Policies
Security, Legal, Finance and Business policies.
Frequent topics and common questions
18
Our Global DPA can be found at https://staffbase.com/en/legal/dpa/
We are committed to providing 99.95% availability of our platform, as outlined in our SLA. This equates to less than nine hours of downtime per year. Service uptime can also be proactively monitored at https://status.staffbase.com.
Yes, Staffbase has a dedicated Information Security team that actively creates, implements, monitors, and enforces security measures throughout the company. We also engage external auditors to assess our controls as part of our annual audits. Staffbase is ISO 27001 certified; a copy of our certification can be found in the Trust Center.
The role of Chief Information Security Officer (CISO) at Staffbase is shared between the Chief Operations Officer (COO) and the Global Head of Information Security. The COO holds executive and organizational responsibility for information security, while the Global Head of Information Security manages the technical and operational aspects.
The Staffbase Security team continuously reviews and implements security controls across the organization. Our COO, Global Head of Information Security, and Security team members can be reached at [email protected]. To learn more about our Information Security team and organizational measures, please continue to explore our Trust Center.
Staffbase's Technical and Organizational Measures (TOMs) are available in Annex III of our DPA .
Public cloud hosting: Staffbase hosting servers are located on Microsoft Azure (in the US, Germany, or Australia). Azure facilities are compliant with ISO 27001 as well as SSAE-16 certification.
Subprocessors
Subprocessors URL
Microsoft Ireland Operations Ltd. (Azure)
This subprocessor is applicable to: Employee App & Front Door Intranet, and New SB Email. Microsoft offers: - ISO 27001 certified data hosting; - When part of Customer’s Order a...
Data location: Germany; USA; Australia
Zendesk, Inc.
This subprocessor is applicable to: Employee App & Front Door Intranet, New SB Email, and Email Classic. Zendesk provides a platform to manage customer support requests. In gene...
Data location: EU
Gainsight, Inc.
This subprocessor is applicable to: Employee App & Front Door Intranet, and New SB Email. We use Gainsight to provide our Digital Customer Success Services to Customer’s primary...
Data location: Germany
Google LLC (Firebase Cloud Messaging)
This subprocessor is applicable to: Employee App & Front Door Intranet. We use Google Firebase Cloud Messaging to send push notifications to the mobile application used by Autho...
Data location: Global
Cloudflare, Inc.
This subprocessor is applicable to: Employee App & Front Door Intranet, and New SB Email. Cloudflare provides: - a Content Delivery Network (CDN) for international distribution...
Data location: EU; USA; Australia
Merge API, Inc.
This subprocessor is applicable to: Employee App & Front Door Intranet. Merge enables Stabase to provide HR Cloud Integrations. By using the HR Cloud Integrations Customer can ...
Data location: EU; USA
Responsible Disclosure
External hackers are also welcome to submit findings through our public page here and automatically get invited to our private bug bounty program at https://hackerone.com.
If you have any security vulnerability to report on Staffbase-owned systems or products, please forward it to [email protected].
Data Privacy & Legal
We are committed to protecting our customer’s personal data. Navigating data protection regulations can be complex. We want to help you understand how our data protection practices satisfy your regulatory needs. Please visit: https://staffbase.com/en/privacy-data-protection/
Our Global DPA can be found at https://staffbase.com/en/legal/dpa/
Other Legal documents and our compliance policies: https://staffbase.com/en/legal/.
Privacy URL