Get Started
Countries
Learn
Company
Store Renew Apply Now →

Trust Center

How RoadSeal protects your data, your money, and your identity. Updated continuously.

256-bit TLS GDPR ready CCPA aligned SOC 2 in progress

At a glance

Uptime & status
0
Data breaches
14d
Grace deletion
24h
DPA response SLA

Security practices

Encryption at rest & in transit

All data encrypted with AES-256 at rest. TLS 1.3 for all network connections. Stripe handles all payment data — we never see card numbers.

Identity verification

Stripe Identity verifies your licence + selfie before issuing your IDP. Identity documents are deleted within 30 days of verification.

Access controls

Row-Level Security on every database table, enforcing isolation between customers and staff. Privileged admin actions are written to an append-only audit log.

Two-factor authentication

The backend supports TOTP-based two-factor authentication (with recovery codes); in-account enrolment is being rolled out.

Vulnerability disclosure

We publish a security.txt and aim to acknowledge good-faith security disclosures within 24 hours.

Backup & recovery

Daily encrypted database backups are managed by our infrastructure provider (Supabase), so data can be restored in the event of a failure.

Compliance & certifications

RoadSeal IDP documents follow the format defined by the United Nations road traffic treaties — the 1949 Geneva Convention on Road Traffic and the 1968 Vienna Convention on Road Traffic. The full treaty texts are available from the UN Treaty Collection. How we verify the claims on this site is documented in our Editorial Policy.

FrameworkStatusLast reviewed
GDPR (Article 17, 20, 25)CompliantQ1 2026
CCPA / CPRAAlignedQ1 2026
UK Data Protection Act 2018CompliantQ1 2026
PCI-DSS (via Stripe)Level 1 inheritedQ4 2025
SOC 2 Type IIIn progress (Q4 2026)
ISO 27001Planned (2027)

Sub-processors

We work with these vendors to operate RoadSeal. Each has signed a DPA aligned with our privacy policy. Last updated April 2026.

VendorPurposeData residency
StripePayment processing & identity verificationUSA / Ireland
Supabase (PostgreSQL)Application database + authEU (Frankfurt)
Cloudflare PagesStatic hosting + CDNGlobal edge
ResendTransactional email deliveryUSA
Anthropic (Claude API)AI chat assistant — when enabled by userUSA
TrustpilotReview collection — opt-inEU (Denmark)
Google (GA4 + Maps)Analytics + address lookup — consent-gatedUSA + Global

Security roadmap

We're an early-stage company building toward formal certification. Below is an honest picture of where we are and what's planned — we don't claim audits we haven't completed.

Planned — 2027

SOC 2 Type II

Independent attestation of security controls over time, once the Type I milestone is complete.

In progress — targeting Q4 2026

SOC 2 Type I

First independent attestation of our security posture at a point in time.

In place today

Row-Level Security across the database

Every application table enforces row-level isolation between customers and staff, with privileged actions written to an append-only audit log.

In place today

Payments & identity handled by Stripe

Card data and identity verification are processed by Stripe (PCI-DSS Level 1); we never store card numbers, and identity documents are deleted within 30 days of verification.

Reporting concerns

Security vulnerability

Email [email protected] with details. PGP key available at /security.txt. We respond within 24 hours.

Privacy / GDPR request

Email [email protected] or use the self-service portal for data export and deletion. 30-day SLA.

Compliance / press

Email [email protected] for legal inquiries, audit cooperation, or press requests for compliance details.

Live status

Real-time uptime, incidents, and maintenance windows on status.roadseal.co.