Custody of the data, on the record.
Sustain360 is a multi-tenant B2B SaaS platform that stores yard operational data, customer records, and audit trails on behalf of its tenants. Security posture is built around three commitments: EU data residency, encryption at rest and in transit, and a documented GDPR position. The detail below is the public summary; the long form is shared with enterprise customers under NDA.
Data handling overview.
- Residency
- European Union. Storage and backup are EU-resident; no customer data leaves the EU as part of normal operations.
- Encryption at rest
- AES-256 with platform-managed keys. Database, file storage, and backups are encrypted.
- Encryption in transit
- TLS 1.2 or higher, modern cipher suites, HSTS preload. No plain-HTTP path is permitted.
- Tenancy isolation
- Role-scoped database connection pools at the data layer. A tenant query cannot read another tenant's rows by design.
- Backups
- Daily encrypted snapshots. Retention is set per tenant in the master agreement; restores are tested on a regular cadence.
- Retention
- Per the tenant's contracted policy. Audit data is preserved for the period required by EU ELV and UK ATF rules.
GDPR posture.
- Data Protection Officer
- privacy@dismanto.com — direct line to the DPO for data subject requests and supervisory authority contact.
- Data subject rights
- Access, rectification, erasure, restriction, portability, and objection — handled within the GDPR-mandated window.
- Processing register
- Documented record of processing activities (Article 30) shared with enterprise customers under NDA.
- Sub-processors
- Current sub-processor list is published to customers; changes are notified before adoption.
The plain-language GDPR statement and current sub-processor list live at /legal/gdpr.
Hosting region
EU-only. Production runs in a Tier-IV EU data centre region with redundant availability zones.
SSO / SAML
SAML 2.0 against any standard IdP, with SCIM provisioning for Entra and Okta. Available on Aggregator Enterprise.
Penetration testing
Annual third-party penetration testing. High-severity findings are remediated under a documented SLA.