Skip to content
Müşavir

Trust Center

How we protect your data, stated plainly

You trust us with accounting, payroll, customer and employee records. This center describes our infrastructure, tenant isolation, backups, subprocessors and certification roadmap without marketing gloss, keeping what is in place today separate from what is a target.

Contact us

How we operate, in short

The platform runs on a Kubernetes cluster we operate ourselves in a data center in Germany, behind Cloudflare. Row-level security is enabled in the database and blocks anonymous reads of personal data. Separation between companies is enforced mainly in the application layer, by the company filter on every query, together with role-based permissions.

  • Browser-to-platform and outbound service connections are TLS-encrypted; integration secrets are stored with AES-256-GCM
  • Target: a database backup every 6 hours; recovery times are also published as targets
  • The subprocessor list is public; changes are announced 30 days in advance
  • Customer data is not used to train AI models

Certification and compliance roadmap

We do not hold a certificate for any of the standards below today. They are roadmap items; the percentage shows the estimated progress of preparation work. Details are on the compliance page.

2026 Q4

VERBİS obligation assessment and registration

Assessing the registration obligation, data inventory and registration if required

%55

2027 Q2

ISO/IEC 27001

Information security management system, roadmap

%35

2027 Q3

ISO/IEC 27701

Privacy information management on top of 27001, roadmap

%20

2027 Q4

SOC 2 Type II

Independent audit after an observation period, roadmap

%10

Trust center pages

Frequently asked questions

Where is my data stored?

The platform and database run in a data center in Germany. Personal data sent from Türkiye to Germany is a cross-border transfer under KVKK Article 9, and we are carrying out the process of signing the Board's standard contracts with recipients and notifying the Authority under Article 9(4)(c). See the KVKK and GDPR page for details.

Is Müşavir ISO 27001 or SOC 2 certified?

No. We hold no certificate for these standards today. ISO/IEC 27001, 27701, 42001, ISO 9001 and SOC 2 Type II are on our roadmap; target quarters and preparation status are published on the compliance page.

Do you sign a data processing agreement?

Yes. As a tenant you are the data controller and we are your processor. We sign a data processing agreement on request; send your request through the contact page.

What should I do if I find a vulnerability?

Follow the steps on the responsible disclosure page and report through the contact page. We do not pursue legal action against good-faith researchers.

Related

Send your question to our security team

Write to us about your procurement review, security questionnaire or data processing agreement request.

Contact us