Security & Trust at Dibsido

Dibsido is the workplace platform teams use to book desks, parking, and meeting rooms - natively inside Microsoft Teams and Slack. We protect the data behind that with the standards you'd expect from a tool your whole office relies on.

This Trust Center is an overview of the controls, certifications, and practices that keep your data secure.

Overview

Controls

Authentication

Resources

Subprocessors

FAQ

Compliance

GDPR compliant

Data Processor DPA available

EU data residency

Microsoft Azure, Germany (Frankfurt)

99% uptime SLA

Guaranteed monthly, with service credits

Standard Contractual Clauses

For any non-EU subprocessor

ISO 27001:2022

Certified

Resources

Security Policies Documentation (v2.0)

Data Processing Agreement (DPA)

ISO 27001 Certificate

Subprocessor list

Controls

AS OF OCTOBER 2026

Infrastructure & Hosting

Hosted on Microsoft Azure - Germany West Central (Frankfurt), EU

Azure App Services and managed services behind platform network protections

Azure SQL Database with Transparent Data Encryption

Storage secured with role-based access control and encryption

Threat detection via Microsoft Defender for Cloud (App Service & SQL workloads)

SQL audit logging enabled (90-day retention)

Encryption

TLS 1.2+ enforced on all endpoints (TLS 1.3 with modern clients)

HSTS on all public-facing endpoints

Encryption at rest via Azure SQL Transparent Data Encryption and Azure Storage encryption

Personal data is permanently deleted on erasure - hard delete, no residual copies

Access control

Role-based access control (Administrator / Operator / User) with least privilege

Multi-factor authentication enforced on all internal accounts

Production access restricted to named senior administrators

Strong password requirements (8+ characters with complexity); secure salted password hashing

Optional 2FA (TOTP) for end users; MFA via your SSO provider

Secure session management: hardened cookies with periodic re-validation of credentials

Application security & vulnerability management

Automated dependency, static-code and dynamic application security scanning

Secret scanning on every code change

Findings triaged and tracked to resolution

Data we process

Customer personal data (name, work email, phone, license plate for parking)

Admin & billing data (company name, billing details)

Payment card data (handled entirely by Stripe, PCI DSS Level 1

Personal health information

Special-category data (not required by the Service)

Subprocessor

Microsoft Azure

Cloud hosting, data storage, security infrastructure

Hosts Dibsido's application, database, and storage in the Germany West Central region. ISO 27001, SOC 2, GDPR.

EU (Germany)

Microsoft (Entra ID/Graph)

Authentication (SSO) & calendar services

Provides enterprise sign-in via Entra ID and calendar integration via Microsoft Graph. OAuth 2.0, limited to the scopes your admin approves.

EU / Global

Google APIs

Authentication (SSO) & calendar sync

Google sign-in and Google Calendar synchronization. OAuth 2.0, limited to the scopes you grant.

Global

Twilio SendGrid

Transactional email

Delivers booking confirmations, invitations, and system notifications. Transfers covered by Standard Contractual Clauses.

USA

FAQ

Are you ISO 27001 certified?

Yes. Dibsido is certified to ISO/IEC 27001:2022 (certificate no. 2609255283, issued 25 September 2026 by TAYLLORCOX, an accredited certification body, valid until 24 September 2029). Scope: development, operation, provision and sale of software.

Does Dibsido encrypt our data?

Yes. In transit with TLS 1.2+ (TLS 1.3 with modern clients, HSTS enforced) and at rest via Azure SQL Transparent Data Encryption.

Where is our data stored?

On Microsoft Azure in the Germany West Central (Frankfurt) region. Your data stays in the EU.

How do you detect threats?

Microsoft Defender for Cloud provides threat detection across our application and database workloads, with continuous monitoring and alerting. SQL audit logging is enabled, and automated vulnerability scanning runs on our codebase and running application.

What SSO options do you support?

Microsoft Entra ID, SAML 2.0 (your own IdP), Okta, WS-Federation, Google Workspace, Google/Microsoft accounts, and Microsoft Teams SSO - plus email + password with optional 2FA, which can be disabled per company.

What uptime do you guarantee?

99% availability per calendar month, backed by service credits. Scheduled maintenance is announced at least 5 days ahead and never performed on working days between 06:00 and 23:00.

Are you GDPR compliant?

Yes. Dibsido acts as a Data Processor on your behalf. Any non-EU subprocessor transfers are covered by Standard Contractual Clauses.

What happens to our data if we leave?

You can export your data at any time via the platform or API. Admins can also delete individual users or the entire company workspace directly in the app. After termination, a 30-day migration period applies for export, after which your data is deleted.

Overview

Compliance

GDPR compliant

Data Processor DPA available

EU data residency

Microsoft Azure, Germany (Frankfurt)

99% uptime SLA

Guaranteed monthly, with service credits

Standard Contractual Clauses

For any non-EU subprocessor

ISO 27001:2022

Certified

Resources

Security Policies Documentation (v2.0)

Data Processing Agreement (DPA)

ISO 27001 Certificate

Subprocessor list

Controls

AS OF OCTOBER 2026

Infrastructure & Hosting

Hosted on Microsoft Azure - Germany West Central (Frankfurt), EU

Azure App Services and managed services behind platform network protections

Azure SQL Database with Transparent Data Encryption

Storage secured with role-based access control and encryption

Threat detection via Microsoft Defender for Cloud (App Service & SQL workloads)

SQL audit logging enabled (90-day retention)

Encryption

TLS 1.2+ enforced on all endpoints (TLS 1.3 with modern clients)

HSTS on all public-facing endpoints

Encryption at rest via Azure SQL Transparent Data Encryption and Azure Storage encryption

Personal data is permanently deleted on erasure - hard delete, no residual copies

Access control

Role-based access control (Administrator / Operator / User) with least privilege

Multi-factor authentication enforced on all internal accounts

Production access restricted to named senior administrators

Strong password requirements (8+ characters with complexity); secure salted password hashing

Optional 2FA (TOTP) for end users; MFA via your SSO provider

Secure session management: hardened cookies with periodic re-validation of credentials

Application security & vulnerability management

Automated dependency, static-code and dynamic application security scanning

Secret scanning on every code change

Findings triaged and tracked to resolution

Data we process

Customer personal data (name, work email, phone, license plate for parking)

Admin & billing data (company name, billing details)

Payment card data (handled entirely by Stripe, PCI DSS Level 1

Personal health information

Special-category data (not required by the Service)

Subprocessor

Microsoft Azure

Cloud hosting, data storage, security infrastructure

Hosts Dibsido's application, database, and storage in the Germany West Central region. ISO 27001, SOC 2, GDPR.

EU (Germany)

Microsoft (Entra ID/Graph)

Authentication (SSO) & calendar services

Provides enterprise sign-in via Entra ID and calendar integration via Microsoft Graph. OAuth 2.0, limited to the scopes your admin approves.

EU / Global

Google APIs

Authentication (SSO) & calendar sync

Google sign-in and Google Calendar synchronization. OAuth 2.0, limited to the scopes you grant.

Global

Twilio SendGrid

Transactional email

Delivers booking confirmations, invitations, and system notifications. Transfers covered by Standard Contractual Clauses.

USA

FAQ

Are you ISO 27001 certified?

Yes. Dibsido is certified to ISO/IEC 27001:2022 (certificate no. 2609255283, issued 25 September 2026 by TAYLLORCOX, an accredited certification body, valid until 24 September 2029). Scope: development, operation, provision and sale of software.

Does Dibsido encrypt our data?

Yes. In transit with TLS 1.2+ (TLS 1.3 with modern clients, HSTS enforced) and at rest via Azure SQL Transparent Data Encryption.

Where is our data stored?

On Microsoft Azure in the Germany West Central (Frankfurt) region. Your data stays in the EU.

How do you detect threats?

Microsoft Defender for Cloud provides threat detection across our application and database workloads, with continuous monitoring and alerting. SQL audit logging is enabled, and automated vulnerability scanning runs on our codebase and running application.

What SSO options do you support?

Microsoft Entra ID, SAML 2.0 (your own IdP), Okta, WS-Federation, Google Workspace, Google/Microsoft accounts, and Microsoft Teams SSO - plus email + password with optional 2FA, which can be disabled per company.

What uptime do you guarantee?

99% availability per calendar month, backed by service credits. Scheduled maintenance is announced at least 5 days ahead and never performed on working days between 06:00 and 23:00.

Are you GDPR compliant?

Yes. Dibsido acts as a Data Processor on your behalf. Any non-EU subprocessor transfers are covered by Standard Contractual Clauses.

What happens to our data if we leave?

You can export your data at any time via the platform or API. Admins can also delete individual users or the entire company workspace directly in the app. After termination, a 30-day migration period applies for export, after which your data is deleted.