Snapshot 62771
Normalized text
Scripts and page chrome removed; this is what change detection compares.
TRUST CENTER One place for security, compliance and privacy. Everything security, legal and procurement teams need to evaluate, approve and monitor DigitalRoute’s data processing practices. View Documents Talk to Support team Security Defense-in-depth, from infrastructure to operations Certified security management, secure data processing and defined SLAs help protect the integrity, confidentiality and availability of customer data. 01 ISO 9001/IEC 27001/SOC I & II Certified Independently audited annually, with full re-certification every three years. Covers access controls, incident handling, change management and continuous monitoring. 02 Continuous Vulnerability Scanning and Remediation (CVE) DigitalRoute continuously scans products and dependencies for CVEs, prioritizes remediation by severity and impact, and provides vulnerability reports for supported releases. 03 Application & Infrastructure Security UsageCloud™ runs on AWS with multi-AZ high availability and containerized workloads, built to handle complex usage data at scale while meeting regulatory standards. 04 Identity, Access & Operations Production access is restricted to authorized personnel. Incidents are classified as critical, major or minor with defined response times. Uptime is reported quarterly. 05 Secure Development Built on Kubernetes with modern DevOps practices. Regular product updates are published for UsageCloud™ and UsageCloud™ Private. 06 Incident Detection & Response SLA defines availability monitoring at one-minute granularity with a target 1-hour response for critical incidents. Service credits apply if minimums are not met as set out in the applicable service level agreement. Status at status.digitalroute.io. 07 Finance-Grade Data Processing UsageCloud™ and MediationZone™ are purpose-built for revenue-impacting data, ensuring that every event is fully auditable, secure and compliant at any volume. Privacy & Data Protection Privacy controls built into every data flow Personal data is processed in accordance with applicable privacy laws and supported by defined policies and technical controls. Privacy Policy & Contact Our Cookie Policy and Data Privacy Policy explain how personal data is collected, used, shared, retained and protected. Please contact us at dpo@digitalroute.com if you have any questions regarding these policies. Legal Bases, Rights & Transparency Personal data is processed on lawful grounds and individuals may exercise their privacy rights in accordance with those laws. Data Minimization & Anonymization Customer data can be masked, de-identified or anonymized before storage, analysis or sharing. Retention, Deletion & Lifecycle Data retention and deletion practices are designed to support customer governance and regulatory requirements. Compliance & Certifications Independently audited. Every year. Our security and quality practices are validated by independent third-party auditors. These certifications cover both DigitalRoute as an organization and specific cloud services, including Usage Engine Cloud Edition™ and UsageCloud™. Certification Scope Achieved Audit Cycle Status ISO/IEC 27001 Information Security Management DigitalRoute organization 2018 Annual surveillance; full re-cert every 3 years Current ISO 9001 Quality Management System DigitalRoute organization 2020 Annual audit Current SOC 2 Type II Security, Availability & Confidentiality UsageCloud™ January 2021 12-month period, independent auditors Current SOC 1 Type II Internal Controls over Financial Reporting UsageCloud™ January 2025 12-month period, independent auditors Current Access to Audit Reports SOC and ISO reports are shared under NDA via your DigitalRoute representative or account team. Email info@digitalroute.com to request access Continuous Vulnerability Scanning and Remediation (CVE) DigitalRoute continuously scans its products and dependencies for known vulnerabilities (CVEs) using OWASP-based software composition analysis built into our build pipelines. Findings are triaged by severity and product impact, with critical issues remediated with the same urgency as customer-reported defects. Vulnerability reports and impact analyses are available to customers on supported releases. Availability & Status High availability, with nowhere to hide Formal SLAs, quarterly reporting and a public status page give full transparency on uptime, maintenance and incidents. 99.9% SLA availability target Measured with one-minute granularity, reported quarterly. Service credits apply if availability falls below the agreed minimum as set out in the applicable service level agreement. SLA Availability is defined as the percentage of time the service can execute scheduled business processes. Incidents are classified as critical, major or minor, each with defined reaction times, including a 1-hour target for critical incidents. Performance data is reported quarterly. Live Status Page View current status, scheduled maintenance and incident history. The Support Portal is available 24/7. View Status Subprocessors & Data Locations Infrastructure you can trust Customers are provided with information about hosting environments, data locations, security responsibilities and controls through formal documentation. Amazon Web Services UsageCloud™ and UsageCloud Private Edition run on AWS using Amazon EKS and AWS Fargate, with high availability across multiple Availability Zones. Deployment Models UsageCloud™ is available as SaaS. UsageCloud Private Edition can be deployed in your own cloud (AWS, GoogleCloud, Azure, OCI) or on premises. Sub-processor Details Sub-processor details are listed in our Data Processing Agreement available on InfoZone. Resources & Documents Everything security, legal and procurement need, in one place Policies, SLAs and technical documents for security, procurement and legal teams. Core Policies & Legal Documents 01 Data Privacy Policy & Cookie Policy Information on personal data processing, privacy rights, cookies and contact details. View privacy policy View cookie policy 02 Cloud Service SLA & Support Service Descriptions Available on InfoZone or request from your DigitalRoute representative View 03 Cloud Service Descriptions Service and Functional Description describing the service made available by DigitalRoute as part of its UsageCloud. View 04 Enterprise Subscription Agreement Contractual documents referenced from the UsageCloud documentation View Security & Compliance Artifacts 01 ISO/IEC 27001 Certificate Information security management— DigitalRoute organization Available on request 02 ISO 9001 Certificate Quality management system — DigitalRoute organization Available on request 03 SOC 1 Type II & SOC 2 Type II Reports UsageCloud™ — available on request under NDA Available on request Product & Platform CONTENT 01 Security & Compliance Overview Certifications for UsageCloud™ and our audit process View 02 AWS Partnership & Architecture Resources UsageCloud on AWS — whitepapers and technical blogs View 03 User Documentation UsageCloud™ and UsageCloud Private Edition — architecture, APIs and operational guidelines View Disclaimer The information on this Trust Centre is provided for general informational purposes only and does not form part of, modify, or supersede any contract between you and DigitalRoute. Service availability targets, service level commitments, service credits, certifications and other details described here are summaries. The binding terms – including availability definitions, measurement methods, exclusions, reaction and resolution targets, and service credit entitlements – are set out solely in the applicable agreement. Certifications and audit reports reflect their status as of their respective audit dates and are subject to their stated scope and audit cycles. DigitalRoute may update, supplement or remove information on this page at any time without notice. In the event of any conflict between this page and a signed agreement, the signed agreement prevails. FAQ Common questions from security and procurement Direct answers for security, privacy and procurement teams. Yes. DigitalRoute holds ISO/IEC 27001 (since 2018) and ISO 9001 (since 2020). UsageCloud™ is SOC 2 Type II certified since 2021 and SOC 1 Type II certified since January 2025, each with annual audit cycles. View current status, scheduled maintenance and incident history at status.digitalroute.io. Our SLA targets 99.9% availability per quarter, measured with one-minute granularity. Service credits apply as set out in the applicable service level agreement if availability falls below the agreed minimum. We process personal data in accordance with applicable privacy laws. For more information, please see our Data Privacy Policy or contact us at dpo@digitalroute.com. UsageCloud™ run on AWS with multi-AZ high availability. Specific regions are defined in customer agreements. Reports are shared under NDA via your DigitalRoute representative. Contact them directly or reach out to info@digitalroute.com to request access. Updates & Announcements Our ongoing investment in trust Key security, compliance and platform milestones. JULY 2025 UsageCloud™ available on AWS Marketplace. JANUARY 2025 UsageCloud™ achieves SOC 1 Type II certification. JANUARY 2021 UsageCloud™ achieves SOC 2 Type II certification. JANUARY 2021 UsageCloud™ launches on Amazon Web Services. 2020 ISO 9001 certification achieved. 2018 ISO/IEC 27001 certification achieved. Contact & Reporting Reach the right team, fast Dedicated contacts for security, privacy and operational questions. Security & Compliance Questions Security, compliance and general trust-related questions info@digitalroute.com Data Protection Personal data, regulatory rights and privacy practices. Check Privacy Policy Customer Support Portal (24/7) Need help troubleshooting, guidance or have questions. Contact Support Need a document or a call with our support team? SOC reports, ISO certificates and DPA agreements available on request. Talk to Support Request Documents