> ## Documentation Index
> Fetch the complete documentation index at: https://docs.stigg.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Security Portal

> Stigg Security and Trust Portal — compliance reports, vulnerability disclosure, and security documentation

Stigg is designed with privacy and security at its core. We maintain **SOC 1 Type II**, **SOC 2 Type II**, and **ISO 27001** certifications, reflecting our commitment to the highest standards of information security and data protection.

Stigg's Security and Trust Portal provides access to compliance reports (SOC 1, SOC 2, GDPR), security documentation, and vulnerability disclosure information. The Security and Trust Portal is available at [security.stigg.io](https://security.stigg.io/).

<img src="https://mintcdn.com/stigg/UlAt5XRaB6FPzp-f/images/docs/05887f4-soc2_1.png?fit=max&auto=format&n=UlAt5XRaB6FPzp-f&q=85&s=eb8454fce553a77fffff1ed42351d811" alt="" width="1058" height="382" data-path="images/docs/05887f4-soc2_1.png" />

## GDPR compliance

While there is no formal EU certification process that allows a company to declare itself "GDPR certified," Stigg provides functionality and safeguards that support GDPR compliance requirements:

* **Customer data archiving**: when a customer is [archived](../managing-customers-and-subscriptions/customers/archiving-customers) in Stigg, all Personal Identifiable Information (PII) previously stored is automatically nullified.
* **Flexible access**: archiving can be done via the Stigg app UI or programmatically using the API and SDKs.
* **Data Processing Agreements (DPAs)**: see below.
* **Privacy by design**: our platform provides the controls needed to respect data subject rights and ensure lawful processing.

GDPR compliance is a **shared responsibility** between Stigg and our customers. Stigg provides the certifications, security practices, and platform features necessary to enable GDPR-aligned usage, while our customers remain responsible for how data is ingested, managed, and retained within their applications.

## Data Processing Agreement (DPA)

Customers of the [Scale Plan](https://www.stigg.io/pricing) that require a Data Processing Agreement (DPA) can request one to be signed as part of their contract with Stigg. More details can be found in our [terms of use](https://www.stigg.io/customer-terms).

<Note>
  For where Stigg stores data, including PII, see [Data residency and PII](./data-residency-and-pii).
</Note>


## Related topics

- [Data residency and PII](/documentation/security-compliance/data-residency-and-pii.md)
- [Customer portal](/documentation/snap-in-widgets/customer-portal.md)
- [Networking, security, and data flow](/documentation/high-availability-and-scale/byoc/networking-and-security.md)
- [Rendering a customer portal](/guides/quick-start-guides/rendering-customer-portal.md)
- [Delta Lake](/documentation/importing-and-exporting-data/export/delta-lake.md)
