SOC 2 Type II
Annual Type II attestation covering security, availability, and confidentiality across all three deployment models. Report available under NDA.
Request the report →Security posture
Every item below is in place today. We do not list aspirational certifications, and we do not put a date on anything until the date is real.
Annual Type II attestation covering security, availability, and confidentiality across all three deployment models. Report available under NDA.
Request the report →DPA available, standard contractual clauses in place, EU data residency supported in Dedicated Managed SaaS and inherent in BYOC.
Request the DPA →Independent third-party penetration testing on an annual cycle, with remediation tracked to closure. Executive summary shareable.
Request the summary →TLS 1.3 in transit, AES-256 at rest. Under BYOC, encryption keys never leave your own KMS.
See architecture →Compliance-grade immutable logging on every connector change, credential rotation, permission grant, and visibility change.
Request log schema →This is the distinction that shortens a six-month vendor risk assessment to weeks. The entire platform, control plane included, runs inside your own cloud account or data center. No cost, usage, telemetry, or workload data crosses your boundary, so there is no processing agreement to negotiate over data we never hold.
Nothing crosses this boundary. No cost data, no usage data, no telemetry, and no workload content reaches DigiUsher. This is why we are assessed as a software provider rather than a data processor.
Multi-tenant, region-selectable. Logical isolation per tenant, encrypted at rest with per-tenant keys. Suitable where no residency mandate applies.
Single-tenant infrastructure in a named region: dedicated VPC, dedicated database. DigiUsher operates it; you own the residency decision.
Deployed via Terraform or Helm through your own CI/CD into your account. Nothing egresses. Every capability, including the governed workflow automation and MCP endpoint, behaves identically.
| Regime | Concern it raises | How BYOC answers it |
|---|---|---|
| FCA / PRA (UK) | Outsourcing and third-party risk in material arrangements; operational resilience. | No data processing outside the firm's own perimeter, so DigiUsher is assessed as software supply rather than critical outsourcing. |
| DORA (EU) | ICT third-party risk register, exit strategy, subcontracting transparency. | FOCUS-native data stays in your estate and is standard-conformant, so exit is a data export you already own rather than a migration project. |
| MAS TRM (Singapore) | Data locality and cloud outsourcing controls for financial institutions. | Deployment inside the institution's own approved cloud account; no cross-border transfer introduced by the tool. |
| FedRAMP / IL2–IL4 (US) | Authorized boundary and government data handling. | BYOC runs within your existing authorized boundary rather than requiring a new external service to be authorized. DigiUsher holds no FedRAMP authorization of its own. |
| Works councils (DE/EU) | Individual-level monitoring of employee activity. | Organization-wide aggregate-only mode disables individual attribution views entirely; individual views are otherwise RBAC-gated. |
This table maps the concerns these regimes raise onto the BYOC deployment model. It is not a claim of certification, authorization, or approval under any of them: BYOC makes DigiUsher a software provider rather than a data processor, which is what simplifies your vendor risk assessment.
Cost tools that observe AI workloads sit uncomfortably close to the most sensitive text in the enterprise. DigiUsher resolves that by architecture rather than policy: conversational content is dropped at the ingestion boundary by rule, regardless of how a connector is configured.
Role-based access control on every surface including the MCP endpoint: an AI assistant inherits exactly the permissions of the person asking, never more. SSO via SAML and OIDC; SCIM provisioning available.
Cloud connectors use read-only roles scoped to billing and metrics APIs. The governed workflow automation never holds write credentials: it raises a pull request into your repository and your approval applies it.
A current subprocessor list is maintained and versioned, with advance notice of material changes. Under BYOC the list is effectively empty, as no third party touches your data. Request the list →
Documented recovery objectives (RTO and RPO), tested restore procedures, and multi-AZ deployment by default. The specific targets are stated in the security pack rather than published here.
Dependency and container scanning in CI, with severity-based remediation SLAs. Coordinated disclosure via security@digiusher.com.
Background checks, annual security training, and role-scoped production access with break-glass approval and full audit trail.
Yes. DigiUsher maintains SOC 2 Type II attestation across all three deployment models: SaaS, Dedicated Managed SaaS, and BYOC. The report is available under NDA on request.
No. AI conversational content (prompts, responses, and tool payloads) is dropped at ingestion by architectural rule, not by configuration. DigiUsher ingests token counts, model identifiers, and cost metadata only, so prompt content cannot be retained even if a client misconfigures a connector.
No. Under Bring Your Own Cloud, the entire platform runs inside the customer's own cloud account or data center and no cost, usage, telemetry, or workload data leaves that perimeter. DigiUsher is therefore classified as a software provider rather than a data processor, which materially simplifies vendor risk assessment under FCA, PRA, MAS, DORA, FedRAMP, and IL2/IL4 regimes.
In SaaS, data is stored in the region you select. In Dedicated Managed SaaS, a single-tenant deployment is pinned to a named region of your choosing. In BYOC, data never leaves your own infrastructure and residency is entirely under your control.
One request returns the whole set: SOC 2 Type II report, DPA with SCCs, penetration test executive summary, BYOC architecture brief, subprocessor list, and a completed CAIQ. Turnaround is typically one business day once an NDA is in place.
The full pack, plus a 45-minute architecture session with our engineering lead to walk your reviewers through the BYOC deployment and answer questions live.
Email security@digiusher.comDPA, SCCs, insurance certificates, MSA template, and marketplace private-offer paperwork. If you are buying through a GSI, we will align to the MSA you already hold with them.
Email sales@digiusher.comPrefer self-serve? Verify our current certifications and request documents directly from our live Trust Center ↗.