Security & Trust at Dibsido

Dibsido is the workplace platform teams use to book desks, parking, and meeting rooms - natively inside Microsoft Teams and Slack. We protect the data behind that with the standards you'd expect from a tool your whole office relies on.

This Trust Center is an overview of the controls, certifications, and practices that keep your data secure.

Overview

Controls

Authentication

Resources

Subprocessors

FAQ

Compliance

GDPR compliant

Data Processor DPA available

EU data residency

Microsoft Azure, Germany (Frankfurt)

99% uptime SLA

Guaranteed monthly, with service credits

Standard Contractual Clauses

For any non-EU subprocessor

ISO 27001

Certification in progress

Resources

Security Policies Documentation (v1.3)

Data Processing Agreement (DPA)

ISO 27001 Certificate

Subprocessor list

Controls

AS OF AUGUST 2026

Infrastructure & Hosting

Hosted on Microsoft Azure - Germany West Central (Frankfurt), EU

Azure App Services and managed services behind platform network protections

Azure SQL Database with Transparent Data Encryption

Storage secured with role-based access control and encryption

Threat detection via Microsoft Defender for Cloud (App Service & SQL workloads)

SQL audit logging enabled (90-day retention)

Encryption

TLS 1.2+ enforced on all endpoints (TLS 1.3 with modern clients)

HSTS on all public-facing endpoints

Encryption at rest via Azure SQL Transparent Data Encryption and Azure Storage encryption

Personal data is permanently deleted on erasure - hard delete, no residual copies

Access control

Role-based access control (Administrator / Operator / User) with least privilege

Multi-factor authentication enforced on all internal accounts

Production access restricted to a small number of named administrators

Strong password requirements (8+ characters with complexity); secure salted password hashing

Optional 2FA (TOTP) for end users; MFA via your SSO provider

Secure session management: hardened cookies with periodic re-validation of credentials

Application security & vulnerability management

Automated dependency, static-code and dynamic application security scanning

Secret scanning with push protection

Findings triaged and tracked to resolution

External penetration test planned as part of the ISO 27001 programme

Data we process

Customer personal data (name, work email, phone, license plate for parking)

Admin & billing data (company name, billing details)

Payment card data (handled entirely by Stripe, PCI DSS Level 1

Personal health information

Special-category data (not required by the Service)

Subprocessor

Microsoft Azure

Cloud hosting, data storage, security infrastructure

Hosts Dibsido's application, database, and storage in the Germany West Central region. ISO 27001, SOC 2, GDPR.

EU (Germany)

Microsoft (Entra ID/Graph)

Authentication (SSO) & calendar services

Provides enterprise sign-in via Entra ID and calendar integration via Microsoft Graph. OAuth 2.0, limited to the scopes your admin approves.

EU / Global

Google APIs

Authentication (SSO) & calendar sync

Google sign-in and Google Calendar synchronization. OAuth 2.0, limited to the scopes you grant.

Global

Twilio SendGrid

Transactional email

Delivers booking confirmations, invitations, and system notifications. Transfers covered by Standard Contractual Clauses.

USA

FAQ

Are you ISO 27001 certified?

Does Dibsido encrypt our data?

Where is our data stored?

How do you detect threats?

What SSO options do you support?

What uptime do you guarantee?

Are you GDPR compliant?

What happens to our data if we leave?

Overview

Compliance

GDPR compliant

Data Processor DPA available

EU data residency

Microsoft Azure, Germany (Frankfurt)

99% uptime SLA

Guaranteed monthly, with service credits

Standard Contractual Clauses

For any non-EU subprocessor

ISO 27001

Certification in progress

Resources

Security Policies Documentation (v1.3)

Data Processing Agreement (DPA)

ISO 27001 Certificate

Subprocessor list

Controls

AS OF AUGUST 2026

Infrastructure & Hosting

Hosted on Microsoft Azure - Germany West Central (Frankfurt), EU

Azure App Services and managed services behind platform network protections

Azure SQL Database with Transparent Data Encryption

Storage secured with role-based access control and encryption

Threat detection via Microsoft Defender for Cloud (App Service & SQL workloads)

SQL audit logging enabled (90-day retention)

Encryption

TLS 1.2+ enforced on all endpoints (TLS 1.3 with modern clients)

HSTS on all public-facing endpoints

Encryption at rest via Azure SQL Transparent Data Encryption and Azure Storage encryption

Personal data is permanently deleted on erasure - hard delete, no residual copies

Access control

Role-based access control (Administrator / Operator / User) with least privilege

Multi-factor authentication enforced on all internal accounts

Production access restricted to a small number of named administrators

Strong password requirements (8+ characters with complexity); secure salted password hashing

Optional 2FA (TOTP) for end users; MFA via your SSO provider

Secure session management: hardened cookies with periodic re-validation of credentials

Application security & vulnerability management

Automated dependency, static-code and dynamic application security scanning

Secret scanning with push protection

Findings triaged and tracked to resolution

External penetration test planned as part of the ISO 27001 programme

Data we process

Customer personal data (name, work email, phone, license plate for parking)

Admin & billing data (company name, billing details)

Payment card data (handled entirely by Stripe, PCI DSS Level 1

Personal health information

Special-category data (not required by the Service)

Subprocessor

Microsoft Azure

Cloud hosting, data storage, security infrastructure

Hosts Dibsido's application, database, and storage in the Germany West Central region. ISO 27001, SOC 2, GDPR.

EU (Germany)

Microsoft (Entra ID/Graph)

Authentication (SSO) & calendar services

Provides enterprise sign-in via Entra ID and calendar integration via Microsoft Graph. OAuth 2.0, limited to the scopes your admin approves.

EU / Global

Google APIs

Authentication (SSO) & calendar sync

Google sign-in and Google Calendar synchronization. OAuth 2.0, limited to the scopes you grant.

Global

Twilio SendGrid

Transactional email

Delivers booking confirmations, invitations, and system notifications. Transfers covered by Standard Contractual Clauses.

USA

FAQ

Are you ISO 27001 certified?

Does Dibsido encrypt our data?

Where is our data stored?

How do you detect threats?

What SSO options do you support?

What uptime do you guarantee?

Are you GDPR compliant?

What happens to our data if we leave?