Security & Trust at Dibsido
Dibsido is the workplace platform teams use to book desks, parking, and meeting rooms - natively inside Microsoft Teams and Slack. We protect the data behind that with the standards you'd expect from a tool your whole office relies on.
This Trust Center is an overview of the controls, certifications, and practices that keep your data secure.
Overview
Controls
Authentication
Resources
Subprocessors
FAQ
Compliance
GDPR compliant
Data Processor DPA available
EU data residency
Microsoft Azure, Germany (Frankfurt)
99% uptime SLA
Guaranteed monthly, with service credits
Standard Contractual Clauses
For any non-EU subprocessor
ISO 27001
Certification in progress
Resources
Security Policies Documentation (v1.3)
Data Processing Agreement (DPA)
ISO 27001 Certificate
Subprocessor list
Controls
AS OF AUGUST 2026
Infrastructure & Hosting
Hosted on Microsoft Azure - Germany West Central (Frankfurt), EU
Azure App Services and managed services behind platform network protections
Azure SQL Database with Transparent Data Encryption
Storage secured with role-based access control and encryption
Threat detection via Microsoft Defender for Cloud (App Service & SQL workloads)
SQL audit logging enabled (90-day retention)
Encryption
TLS 1.2+ enforced on all endpoints (TLS 1.3 with modern clients)
HSTS on all public-facing endpoints
Encryption at rest via Azure SQL Transparent Data Encryption and Azure Storage encryption
Personal data is permanently deleted on erasure - hard delete, no residual copies
Access control
Role-based access control (Administrator / Operator / User) with least privilege
Multi-factor authentication enforced on all internal accounts
Production access restricted to a small number of named administrators
Strong password requirements (8+ characters with complexity); secure salted password hashing
Optional 2FA (TOTP) for end users; MFA via your SSO provider
Secure session management: hardened cookies with periodic re-validation of credentials
Application security & vulnerability management
Automated dependency, static-code and dynamic application security scanning
Secret scanning with push protection
Findings triaged and tracked to resolution
External penetration test planned as part of the ISO 27001 programme
Data we process
Customer personal data (name, work email, phone, license plate for parking)
Admin & billing data (company name, billing details)
Payment card data (handled entirely by Stripe, PCI DSS Level 1
Personal health information
Special-category data (not required by the Service)
Subprocessor
Microsoft Azure
Cloud hosting, data storage, security infrastructure
Hosts Dibsido's application, database, and storage in the Germany West Central region. ISO 27001, SOC 2, GDPR.
EU (Germany)
Microsoft (Entra ID/Graph)
Authentication (SSO) & calendar services
Provides enterprise sign-in via Entra ID and calendar integration via Microsoft Graph. OAuth 2.0, limited to the scopes your admin approves.
EU / Global
Google APIs
Authentication (SSO) & calendar sync
Google sign-in and Google Calendar synchronization. OAuth 2.0, limited to the scopes you grant.
Global
Twilio SendGrid
Transactional email
Delivers booking confirmations, invitations, and system notifications. Transfers covered by Standard Contractual Clauses.
USA
FAQ
Are you ISO 27001 certified?
Does Dibsido encrypt our data?
Where is our data stored?
How do you detect threats?
What SSO options do you support?
What uptime do you guarantee?
Are you GDPR compliant?
What happens to our data if we leave?
Overview
Compliance
GDPR compliant
Data Processor DPA available
EU data residency
Microsoft Azure, Germany (Frankfurt)
99% uptime SLA
Guaranteed monthly, with service credits
Standard Contractual Clauses
For any non-EU subprocessor
ISO 27001
Certification in progress
Resources
Security Policies Documentation (v1.3)
Data Processing Agreement (DPA)
ISO 27001 Certificate
Subprocessor list
Controls
AS OF AUGUST 2026
Infrastructure & Hosting
Hosted on Microsoft Azure - Germany West Central (Frankfurt), EU
Azure App Services and managed services behind platform network protections
Azure SQL Database with Transparent Data Encryption
Storage secured with role-based access control and encryption
Threat detection via Microsoft Defender for Cloud (App Service & SQL workloads)
SQL audit logging enabled (90-day retention)
Encryption
TLS 1.2+ enforced on all endpoints (TLS 1.3 with modern clients)
HSTS on all public-facing endpoints
Encryption at rest via Azure SQL Transparent Data Encryption and Azure Storage encryption
Personal data is permanently deleted on erasure - hard delete, no residual copies
Access control
Role-based access control (Administrator / Operator / User) with least privilege
Multi-factor authentication enforced on all internal accounts
Production access restricted to a small number of named administrators
Strong password requirements (8+ characters with complexity); secure salted password hashing
Optional 2FA (TOTP) for end users; MFA via your SSO provider
Secure session management: hardened cookies with periodic re-validation of credentials
Application security & vulnerability management
Automated dependency, static-code and dynamic application security scanning
Secret scanning with push protection
Findings triaged and tracked to resolution
External penetration test planned as part of the ISO 27001 programme
Data we process
Customer personal data (name, work email, phone, license plate for parking)
Admin & billing data (company name, billing details)
Payment card data (handled entirely by Stripe, PCI DSS Level 1
Personal health information
Special-category data (not required by the Service)
Subprocessor
Microsoft Azure
Cloud hosting, data storage, security infrastructure
Hosts Dibsido's application, database, and storage in the Germany West Central region. ISO 27001, SOC 2, GDPR.
EU (Germany)
Microsoft (Entra ID/Graph)
Authentication (SSO) & calendar services
Provides enterprise sign-in via Entra ID and calendar integration via Microsoft Graph. OAuth 2.0, limited to the scopes your admin approves.
EU / Global
Google APIs
Authentication (SSO) & calendar sync
Google sign-in and Google Calendar synchronization. OAuth 2.0, limited to the scopes you grant.
Global
Twilio SendGrid
Transactional email
Delivers booking confirmations, invitations, and system notifications. Transfers covered by Standard Contractual Clauses.
USA
FAQ
Are you ISO 27001 certified?
Does Dibsido encrypt our data?
Where is our data stored?
How do you detect threats?
What SSO options do you support?
What uptime do you guarantee?
Are you GDPR compliant?
What happens to our data if we leave?