Security & Trust at Dibsido
Dibsido is the workplace platform teams use to book desks, parking, and meeting rooms - natively inside Microsoft Teams and Slack. We protect the data behind that with the standards you'd expect from a tool your whole office relies on.
This Trust Center is an overview of the controls, certifications, and practices that keep your data secure.
Overview
Controls
Authentication
Resources
Subprocessors
FAQ
Compliance
GDPR compliant
Data Processor DPA available
EU data residency
Microsoft Azure, Germany (Frankfurt)
99% uptime SLA
Guaranteed monthly, with service credits
Standard Contractual Clauses
For any non-EU subprocessor
ISO 27001:2022
Certified
Resources
Security Policies Documentation (v2.0)
Data Processing Agreement (DPA)
ISO 27001 Certificate
Subprocessor list
Controls
AS OF OCTOBER 2026
Infrastructure & Hosting
Hosted on Microsoft Azure - Germany West Central (Frankfurt), EU
Azure App Services and managed services behind platform network protections
Azure SQL Database with Transparent Data Encryption
Storage secured with role-based access control and encryption
Threat detection via Microsoft Defender for Cloud (App Service & SQL workloads)
SQL audit logging enabled (90-day retention)
Encryption
TLS 1.2+ enforced on all endpoints (TLS 1.3 with modern clients)
HSTS on all public-facing endpoints
Encryption at rest via Azure SQL Transparent Data Encryption and Azure Storage encryption
Personal data is permanently deleted on erasure - hard delete, no residual copies
Access control
Role-based access control (Administrator / Operator / User) with least privilege
Multi-factor authentication enforced on all internal accounts
Production access restricted to named senior administrators
Strong password requirements (8+ characters with complexity); secure salted password hashing
Optional 2FA (TOTP) for end users; MFA via your SSO provider
Secure session management: hardened cookies with periodic re-validation of credentials
Application security & vulnerability management
Automated dependency, static-code and dynamic application security scanning
Secret scanning on every code change
Findings triaged and tracked to resolution
Data we process
Customer personal data (name, work email, phone, license plate for parking)
Admin & billing data (company name, billing details)
Payment card data (handled entirely by Stripe, PCI DSS Level 1
Personal health information
Special-category data (not required by the Service)
Subprocessor
Microsoft Azure
Cloud hosting, data storage, security infrastructure
Hosts Dibsido's application, database, and storage in the Germany West Central region. ISO 27001, SOC 2, GDPR.
EU (Germany)
Microsoft (Entra ID/Graph)
Authentication (SSO) & calendar services
Provides enterprise sign-in via Entra ID and calendar integration via Microsoft Graph. OAuth 2.0, limited to the scopes your admin approves.
EU / Global
Google APIs
Authentication (SSO) & calendar sync
Google sign-in and Google Calendar synchronization. OAuth 2.0, limited to the scopes you grant.
Global
Twilio SendGrid
Transactional email
Delivers booking confirmations, invitations, and system notifications. Transfers covered by Standard Contractual Clauses.
USA
FAQ
Are you ISO 27001 certified?
Yes. Dibsido is certified to ISO/IEC 27001:2022 (certificate no. 2609255283, issued 25 September 2026 by TAYLLORCOX, an accredited certification body, valid until 24 September 2029). Scope: development, operation, provision and sale of software.
Does Dibsido encrypt our data?
Yes. In transit with TLS 1.2+ (TLS 1.3 with modern clients, HSTS enforced) and at rest via Azure SQL Transparent Data Encryption.
Where is our data stored?
On Microsoft Azure in the Germany West Central (Frankfurt) region. Your data stays in the EU.
How do you detect threats?
Microsoft Defender for Cloud provides threat detection across our application and database workloads, with continuous monitoring and alerting. SQL audit logging is enabled, and automated vulnerability scanning runs on our codebase and running application.
What SSO options do you support?
Microsoft Entra ID, SAML 2.0 (your own IdP), Okta, WS-Federation, Google Workspace, Google/Microsoft accounts, and Microsoft Teams SSO - plus email + password with optional 2FA, which can be disabled per company.
What uptime do you guarantee?
99% availability per calendar month, backed by service credits. Scheduled maintenance is announced at least 5 days ahead and never performed on working days between 06:00 and 23:00.
Are you GDPR compliant?
Yes. Dibsido acts as a Data Processor on your behalf. Any non-EU subprocessor transfers are covered by Standard Contractual Clauses.
What happens to our data if we leave?
You can export your data at any time via the platform or API. Admins can also delete individual users or the entire company workspace directly in the app. After termination, a 30-day migration period applies for export, after which your data is deleted.
Overview
Compliance
GDPR compliant
Data Processor DPA available
EU data residency
Microsoft Azure, Germany (Frankfurt)
99% uptime SLA
Guaranteed monthly, with service credits
Standard Contractual Clauses
For any non-EU subprocessor
ISO 27001:2022
Certified
Resources
Security Policies Documentation (v2.0)
Data Processing Agreement (DPA)
ISO 27001 Certificate
Subprocessor list
Controls
AS OF OCTOBER 2026
Infrastructure & Hosting
Hosted on Microsoft Azure - Germany West Central (Frankfurt), EU
Azure App Services and managed services behind platform network protections
Azure SQL Database with Transparent Data Encryption
Storage secured with role-based access control and encryption
Threat detection via Microsoft Defender for Cloud (App Service & SQL workloads)
SQL audit logging enabled (90-day retention)
Encryption
TLS 1.2+ enforced on all endpoints (TLS 1.3 with modern clients)
HSTS on all public-facing endpoints
Encryption at rest via Azure SQL Transparent Data Encryption and Azure Storage encryption
Personal data is permanently deleted on erasure - hard delete, no residual copies
Access control
Role-based access control (Administrator / Operator / User) with least privilege
Multi-factor authentication enforced on all internal accounts
Production access restricted to named senior administrators
Strong password requirements (8+ characters with complexity); secure salted password hashing
Optional 2FA (TOTP) for end users; MFA via your SSO provider
Secure session management: hardened cookies with periodic re-validation of credentials
Application security & vulnerability management
Automated dependency, static-code and dynamic application security scanning
Secret scanning on every code change
Findings triaged and tracked to resolution
Data we process
Customer personal data (name, work email, phone, license plate for parking)
Admin & billing data (company name, billing details)
Payment card data (handled entirely by Stripe, PCI DSS Level 1
Personal health information
Special-category data (not required by the Service)
Subprocessor
Microsoft Azure
Cloud hosting, data storage, security infrastructure
Hosts Dibsido's application, database, and storage in the Germany West Central region. ISO 27001, SOC 2, GDPR.
EU (Germany)
Microsoft (Entra ID/Graph)
Authentication (SSO) & calendar services
Provides enterprise sign-in via Entra ID and calendar integration via Microsoft Graph. OAuth 2.0, limited to the scopes your admin approves.
EU / Global
Google APIs
Authentication (SSO) & calendar sync
Google sign-in and Google Calendar synchronization. OAuth 2.0, limited to the scopes you grant.
Global
Twilio SendGrid
Transactional email
Delivers booking confirmations, invitations, and system notifications. Transfers covered by Standard Contractual Clauses.
USA
FAQ
Are you ISO 27001 certified?
Yes. Dibsido is certified to ISO/IEC 27001:2022 (certificate no. 2609255283, issued 25 September 2026 by TAYLLORCOX, an accredited certification body, valid until 24 September 2029). Scope: development, operation, provision and sale of software.
Does Dibsido encrypt our data?
Yes. In transit with TLS 1.2+ (TLS 1.3 with modern clients, HSTS enforced) and at rest via Azure SQL Transparent Data Encryption.
Where is our data stored?
On Microsoft Azure in the Germany West Central (Frankfurt) region. Your data stays in the EU.
How do you detect threats?
Microsoft Defender for Cloud provides threat detection across our application and database workloads, with continuous monitoring and alerting. SQL audit logging is enabled, and automated vulnerability scanning runs on our codebase and running application.
What SSO options do you support?
Microsoft Entra ID, SAML 2.0 (your own IdP), Okta, WS-Federation, Google Workspace, Google/Microsoft accounts, and Microsoft Teams SSO - plus email + password with optional 2FA, which can be disabled per company.
What uptime do you guarantee?
99% availability per calendar month, backed by service credits. Scheduled maintenance is announced at least 5 days ahead and never performed on working days between 06:00 and 23:00.
Are you GDPR compliant?
Yes. Dibsido acts as a Data Processor on your behalf. Any non-EU subprocessor transfers are covered by Standard Contractual Clauses.
What happens to our data if we leave?
You can export your data at any time via the platform or API. Admins can also delete individual users or the entire company workspace directly in the app. After termination, a 30-day migration period applies for export, after which your data is deleted.