Encryption
TLS 1.3 in transit. AES-256-GCM at rest with a data key per end user wrapped by a per-tenant KMS key. Erasure destroys the key.
Everything a vendor review needs, in one place: how data is protected, where it lives, who processes it, and how to get the paperwork.
TLS 1.3 in transit. AES-256-GCM at rest with a data key per end user wrapped by a per-tenant KMS key. Erasure destroys the key.
Text, inputs, and images are masked on the device before upload. Privacy mode is on by default and masks all text. Passwords, card details, and one-time codes are always hidden. A server-side scanner quarantines suspected leaks.
SSO (SAML 2.0, OIDC), MFA with passkeys or TOTP, role-based access with least-privilege roles, just-in-time elevated access with approval, IP allowlists.
Immutable audit log of every replay view, export, unmask, live-assist action, AI query, and admin change, retained six years and exportable to your SIEM.
Independent US and EU stacks. No cross-region replication of customer data.
Row-level security and per-tenant keys by default; dedicated clusters and a PHI enclave for Enterprise.
Multi-AZ managed data stores and nightly backups with continuous log archiving, kept inside the residency boundary. Recovery objectives are published here once a restore drill has measured them.
Tagged releases are signed and ship a software bill of materials; images are scanned for known vulnerabilities and pull requests for secrets and risky dependencies; memory-bounded load tests and chaos tests run in CI; privacy review on every collector change.
| Framework | Status | Notes |
|---|---|---|
| SOC 2 Type II | In progress | Audit window opens with the first enterprise customer; report available under NDA when issued. |
| HIPAA | Available | BAA on the Enterprise plan; PHI enclave with AI processing pinned to your residency region. |
| GDPR / UK GDPR | Available | DPA with SCCs, DSAR export, cryptographic erasure, EU residency. |
| CCPA / CPRA | Available | GPC honored automatically; opt-out API. |
| HITRUST r2 | Planned | Readiness assessment in year two. |
| ISO 27001 | Planned | Following SOC 2. |
Business Associate Agreement on the Enterprise plan. PHI enclave with dedicated keys, AI processing pinned to your residency region, 15-minute idle logoff, six-year audit retention, breach notification within the HIPAA window. Healthcare details →
DPA with Standard Contractual Clauses, EU-only stack for EU customers, consent adapters, DSAR export in one click, cryptographic erasure per end user with receipts, DPIA template on request.
We do not sell personal information. Global Privacy Control is honored automatically by the SDK; an opt-out API stops recording and requests deletion.
Primary in us-east-1, disaster recovery in us-west-2. Available on every plan.
Primary in eu-west-1, disaster recovery in eu-central-1. Available on Business and Enterprise. AI inference pinned to the EU where the provider supports it.
| Subprocessor | Purpose | Location | Data | BAA |
|---|---|---|---|---|
| Amazon Web Services | Cloud infrastructure: compute, object storage, databases, KMS, email delivery | United States (us-east-1, us-west-2); European Union (eu-west-1, eu-central-1) | All customer data, encrypted at rest with per-tenant keys | Yes |
| ClickHouse, Inc. | Managed analytics database for flattened event data | Same region as the customer's stack | Event metadata (no replay pixels, no masked text) | Yes (dedicated tier) |
| AI inference provider (non-PHI tenants) | AI analysis for tenants that do not process PHI | United States | Masked session data | Not used for PHI tenants |
| AI inference provider (PHI tenants) | AI analysis for PHI tenants, inside the tenant's residency region | Customer's residency region | Masked session data | Yes |
| Grafana Labs | Platform observability (metrics, logs, traces of our own services) | United States / EU | Operational telemetry only; never payloads | Not required |
| Stripe | Billing and payments | United States | Billing contact and payment details | Not required |
| GitHub | Source control integration, when connected by the customer | United States | Repository metadata, PR drafts | Not required |
Named AI inference providers, with their regions and BAA status, are listed in the DPA and available under NDA. Customers receive 30 days' notice by email to their organization owners before a new subprocessor is added.
Annual third-party test. Executive summary available on request; full report under NDA.
Report available under NDA when issued. Until then, our control matrix and policies are available for review.
Architecture overview, data flow diagrams, and a DPIA template pre-filled for session replay.
Tell us who you are and what you need. A human replies within one business day with the documents or a scheduled review.
Security disclosures: hello@backstory.io. We acknowledge within two business days and do not pursue researchers acting in good faith.