Get Started
Countries
Learn
Company
Store Renew Apply Now →

Trust Center

How RoadSeal protects your data, your money, and your identity. Updated continuously.

256-bit TLS GDPR ready CCPA aligned SOC 2 in progress

At a glance

99.98%
Uptime (90d)
0
Data breaches
14d
Grace deletion
24h
DPA response SLA

Security practices

Encryption at rest & in transit

All data encrypted with AES-256 at rest. TLS 1.3 for all network connections. Stripe handles all payment data — we never see card numbers.

Identity verification

Stripe Identity verifies your licence + selfie before issuing your IDP. Identity documents are deleted within 30 days of verification.

Access controls

Row-Level Security on every database table. Admin actions audit-logged. Two-person review required for refunds >$200 and account deletions.

Two-factor authentication

Optional TOTP-based 2FA for customer accounts. Mandatory for all admin accounts. Recovery codes provided at enrollment.

Vulnerability disclosure

We publish a security.txt and respond to disclosures within 24 hours. Bug bounty program live for verified researchers.

Backup & recovery

Daily encrypted backups across 3 geographic regions. Tested recovery SLA: 4 hours. Audited quarterly.

Compliance & certifications

RoadSeal IDP documents follow the format defined by the United Nations road traffic treaties — the 1949 Geneva Convention on Road Traffic and the 1968 Vienna Convention on Road Traffic. The full treaty texts are available from the UN Treaty Collection. How we verify the claims on this site is documented in our Editorial Policy.

FrameworkStatusLast reviewed
GDPR (Article 17, 20, 25)CompliantQ1 2026
CCPA / CPRAAlignedQ1 2026
UK Data Protection Act 2018CompliantQ1 2026
PCI-DSS (via Stripe)Level 1 inheritedQ4 2025
SOC 2 Type IIIn progress (Q4 2026)
ISO 27001Planned (2027)

Sub-processors

We work with these vendors to operate RoadSeal. Each has signed a DPA aligned with our privacy policy. Last updated April 2026.

VendorPurposeData residency
StripePayment processing & identity verificationUSA / Ireland
Supabase (PostgreSQL)Application database + authEU (Frankfurt)
Cloudflare PagesStatic hosting + CDNGlobal edge
SendGridTransactional email deliveryUSA
Anthropic (Claude API)AI chat assistant — when enabled by userUSA
TrustpilotReview collection — opt-inEU (Denmark)
Google (GA4 + Maps)Analytics + address lookup — consent-gatedUSA + Global

Audit timeline

Q1 2027 (planned)

SOC 2 Type II certification

Annual review of all security controls by a CPA firm.

Q4 2026 (in progress)

SOC 2 Type I report

First milestone — independent attestation of security posture.

February 2026

Penetration test — passed

Independent external pen test by Cobalt.io. 0 critical findings, 2 medium, 4 low — all remediated within 14 days.

November 2025

GDPR DPIA completed

Data Protection Impact Assessment for IDP processing flow. Reviewed by external DPO.

June 2025

RLS audit on all 21 tables

Every table verified to enforce row-level isolation between customers and admins.

Reporting concerns

Security vulnerability

Email security@roadseal.co with details. PGP key available at /security.txt. We respond within 24 hours.

Privacy / GDPR request

Email dpo@roadseal.co or use the self-service portal for data export and deletion. 30-day SLA.

Compliance / press

Email legal@roadseal.co for legal inquiries, audit cooperation, or press requests for compliance details.

Live status

Real-time uptime, incidents, and maintenance windows on status.roadseal.co.