Menu Home
ProductReplay & DevToolsSignalsCall qualityWhy (AI)Live AssistCanvas recordingPrivacy & complianceSelf-hosted
SolutionsHealthcare & virtual careEngineeringSupportProduct teamsKiosks & monitoring
MorePricingDocsCompareTrust centerGlossaryAboutContactPress kit
Log inStart free
Trust center

The page your compliance officer will link.

Everything a vendor review needs, in one place: how data is protected, where it lives, who processes it, and how to get the paperwork.

Security overview

Controls, stated plainly.

Encryption

TLS 1.3 in transit. AES-256-GCM at rest with a data key per end user wrapped by a per-tenant KMS key. Erasure destroys the key.

Masking

Text, inputs, and images are masked on the device before upload. Privacy mode is on by default and masks all text. Passwords, card details, and one-time codes are always hidden. A server-side scanner quarantines suspected leaks.

Access control

SSO (SAML 2.0, OIDC), MFA with passkeys or TOTP, role-based access with least-privilege roles, just-in-time elevated access with approval, IP allowlists.

Audit

Immutable audit log of every replay view, export, unmask, live-assist action, AI query, and admin change, retained six years and exportable to your SIEM.

Residency

Independent US and EU stacks. No cross-region replication of customer data.

Isolation

Row-level security and per-tenant keys by default; dedicated clusters and a PHI enclave for Enterprise.

Resilience

Multi-AZ managed data stores and nightly backups with continuous log archiving, kept inside the residency boundary. Recovery objectives are published here once a restore drill has measured them.

Secure development

Tagged releases are signed and ship a software bill of materials; images are scanned for known vulnerabilities and pull requests for secrets and risky dependencies; memory-bounded load tests and chaos tests run in CI; privacy review on every collector change.

Compliance

Regulations and certifications.

Compliance status
FrameworkStatusNotes
SOC 2 Type IIIn progressAudit window opens with the first enterprise customer; report available under NDA when issued.
HIPAAAvailableBAA on the Enterprise plan; PHI enclave with AI processing pinned to your residency region.
GDPR / UK GDPRAvailableDPA with SCCs, DSAR export, cryptographic erasure, EU residency.
CCPA / CPRAAvailableGPC honored automatically; opt-out API.
HITRUST r2PlannedReadiness assessment in year two.
ISO 27001PlannedFollowing SOC 2.

HIPAA

Business Associate Agreement on the Enterprise plan. PHI enclave with dedicated keys, AI processing pinned to your residency region, 15-minute idle logoff, six-year audit retention, breach notification within the HIPAA window. Healthcare details →

GDPR / UK GDPR

DPA with Standard Contractual Clauses, EU-only stack for EU customers, consent adapters, DSAR export in one click, cryptographic erasure per end user with receipts, DPIA template on request.

CCPA / CPRA

We do not sell personal information. Global Privacy Control is honored automatically by the SDK; an opt-out API stops recording and requests deletion.

Data residency

Two stacks. No replication between them.

United States

Primary in us-east-1, disaster recovery in us-west-2. Available on every plan.

European Union

Primary in eu-west-1, disaster recovery in eu-central-1. Available on Business and Enterprise. AI inference pinned to the EU where the provider supports it.

Subprocessors

Who else touches data, and why.

Subprocessor list
SubprocessorPurposeLocationDataBAA
Amazon Web ServicesCloud infrastructure: compute, object storage, databases, KMS, email deliveryUnited States (us-east-1, us-west-2); European Union (eu-west-1, eu-central-1)All customer data, encrypted at rest with per-tenant keysYes
ClickHouse, Inc.Managed analytics database for flattened event dataSame region as the customer's stackEvent metadata (no replay pixels, no masked text)Yes (dedicated tier)
AI inference provider (non-PHI tenants)AI analysis for tenants that do not process PHIUnited StatesMasked session dataNot used for PHI tenants
AI inference provider (PHI tenants)AI analysis for PHI tenants, inside the tenant's residency regionCustomer's residency regionMasked session dataYes
Grafana LabsPlatform observability (metrics, logs, traces of our own services)United States / EUOperational telemetry only; never payloadsNot required
StripeBilling and paymentsUnited StatesBilling contact and payment detailsNot required
GitHubSource control integration, when connected by the customerUnited StatesRepository metadata, PR draftsNot required

Named AI inference providers, with their regions and BAA status, are listed in the DPA and available under NDA. Customers receive 30 days' notice by email to their organization owners before a new subprocessor is added.

Reports

Documents available under NDA.

Penetration test summary

Annual third-party test. Executive summary available on request; full report under NDA.

SOC 2 Type II

Report available under NDA when issued. Until then, our control matrix and policies are available for review.

Architecture and DPIA

Architecture overview, data flow diagrams, and a DPIA template pre-filled for session replay.

Paperwork

Request a DPA, BAA, or security review.

Tell us who you are and what you need. A human replies within one business day with the documents or a scheduled review.

Security disclosures: hello@backstory.io. We acknowledge within two business days and do not pursue researchers acting in good faith.