§ — Security and GDPR

Custody of the data, on the record.

Sustain360 is a multi-tenant B2B SaaS platform that stores yard operational data, customer records, and audit trails on behalf of its tenants. Security posture is built around three commitments: EU data residency, encryption at rest and in transit, and a documented GDPR position. The detail below is the public summary; the long form is shared with enterprise customers under NDA.

Data handling overview.

Residency
European Union. Storage and backup are EU-resident; no customer data leaves the EU as part of normal operations.
Encryption at rest
AES-256 with platform-managed keys. Database, file storage, and backups are encrypted.
Encryption in transit
TLS 1.2 or higher, modern cipher suites, HSTS preload. No plain-HTTP path is permitted.
Tenancy isolation
Role-scoped database connection pools at the data layer. A tenant query cannot read another tenant's rows by design.
Backups
Daily encrypted snapshots. Retention is set per tenant in the master agreement; restores are tested on a regular cadence.
Retention
Per the tenant's contracted policy. Audit data is preserved for the period required by EU ELV and UK ATF rules.

GDPR posture.

Data Protection Officer
privacy@dismanto.com — direct line to the DPO for data subject requests and supervisory authority contact.
Data subject rights
Access, rectification, erasure, restriction, portability, and objection — handled within the GDPR-mandated window.
Processing register
Documented record of processing activities (Article 30) shared with enterprise customers under NDA.
Sub-processors
Current sub-processor list is published to customers; changes are notified before adoption.

The plain-language GDPR statement and current sub-processor list live at /legal/gdpr.

Hosting region

EU-only. Production runs in a Tier-IV EU data centre region with redundant availability zones.

SSO / SAML

SAML 2.0 against any standard IdP, with SCIM provisioning for Entra and Okta. Available on Aggregator Enterprise.

Penetration testing

Annual third-party penetration testing. High-severity findings are remediated under a documented SLA.

Questions about security.

Related reading

§ — Security review

Need the long form?
We share it under NDA.

A short walk-through of the configurable workflow, the aggregator–yard tenant model, and the integrations relevant to your stack.