Trust Center
How we protect your data
SavvyIT operates infrastructure on behalf of hosting providers and SaaS platforms. This page documents our security posture, compliance alignment, and incident commitments — in plain language, not marketing.
How we work with clients
SavvyIT operates in two infrastructure modes depending on the engagement:
SavvyIT-managed infrastructure
We provide and manage the servers, cloud accounts, and monitoring on your behalf. SavvyIT is the data processor for all infrastructure in scope, and the vendors listed below are our subprocessors.
Client-provided infrastructure
You bring your own cloud accounts, dedicated servers, or managed services. We work inside your existing vendor relationships under your instructions. Your own agreement with each vendor governs data processing — SavvyIT acts purely as a processor under your direction and claims no independent data processing rights.
Both modes use many of the same underlying vendors. The subprocessor list below applies to either mode — the difference is whose account holds the data.
Compliance alignment
We align our processes to SOC 2 Trust Services Criteria and GDPR data protection requirements.
- SOC 2 Trust Services Criteria — aligned
- GDPR — controller/processor roles documented
- PCI-DSS practices — no raw card data stored
- Data Processing Agreement (DPA) available on request
Data & security
Encryption everywhere, least-privilege access, and no permanent employee access to production data without a ticket trail.
- TLS 1.3 in transit, AES-256 at rest
- Secrets in HashiCorp Vault / 1Password Business
- 2FA enforced on every staff account
- EU data remains in the EU by default; SCCs in place for cross-border transfers
Incident response
Every incident gets a documented timeline, a postmortem, and a fix. Clients are notified within contractual windows.
- Sev-1 acknowledgement within 15 minutes
- Client notification within 72 hours (GDPR Art. 33)
- Public postmortem on request within 5 business days
- Root-cause remediation tracked to closure
Access & personnel
Every staff member is background-checked, NDA-bound, and works under least-privilege roles.
- Signed NDAs before production access
- Role-based access control; no shared credentials
- Offboarding removes access within 4 hours
- Annual security awareness training
Non-negotiables
What we will never do
We never sell or rent client data.
We never use client data to train AI models.
We never store raw credit card numbers.
We never grant third parties access without written client authorization.
Subprocessors
We use a small set of well-known vendors to deliver our services. The list below is complete and current — we never add a subprocessor that handles client data without notifying you 30 days in advance.
Client infrastructure
Vendors that run client workloads in SavvyIT-managed engagements. When a client provides their own infrastructure (see above), these same vendors may be used inside the client's own accounts.
- AWSGlobal (EU + US)Primary cloud compute & storage
- Microsoft AzureGlobal (EU + US)Client cloud workloads
- Google Cloud PlatformGlobal (EU + US)Client cloud workloads
- DigitalOceanEU + USVPS hosting, managed databases
- VultrGlobal (20+ regions)VPS hosting, edge compute
- LeasewebEU + USVPS & dedicated bare-metal
- AvoroGermanyVPS, dedicated servers & colocation
- HetznerEUDedicated servers, VPS
- CloudflareGlobal edgeDNS, WAF, DDoS protection
Client operations
Vendors that process client business data long-term.
- FOSSBillingSelf-hosted (EU)Client billing & invoicing
- FreeScoutSelf-hosted (EU)Helpdesk & client support
- UptimeRobotGlobalClient uptime monitoring
- BetterStackEULogs & incident alerting
- HetrixToolsGlobalServer monitoring, blacklist tracking
Client communications
Vendors that handle outbound mail or support conversations on behalf of clients.
- AWS SESEU + USTransactional email
- MailgunEU + USTransactional email & inbound routing
- ResendEU + USTransactional email (developer API)
- MailtrapEUEmail testing & staging
- TelegramGlobalClient support channel (opt-in)
Payments & billing
Vendors that handle payment processing. Card data never touches our systems.
- StripeGlobalCard payments, subscription billing
- PayPalGlobalAlternative payments
- NOWPaymentsGlobalCrypto payments (BTC, USDT, ETH, 100+ coins)
- CryptomusGlobalCrypto payments (backup processor)
Last updated: February 2026. We notify clients 30 days before adding or replacing a subprocessor that handles client data.
Report a vulnerability
If you believe you've found a security issue in any of our systems, email us — we'll acknowledge within 24 hours and never take legal action against good-faith research.
PGP key available on request.
Documents available on request
- Data Processing Agreement (GDPR Art. 28)Request
- Subprocessor list with regions and purposesRequest
- Standard Contractual Clauses (SCCs) for cross-border transfersRequest
- Security questionnaire response (CAIQ-lite / SIG-lite)Request
Documents are provided under NDA. Turnaround is typically one business day.