TRUST CENTER
One place for security, compliance and privacy.
Everything security, legal and procurement teams need to evaluate, approve and monitor DigitalRoute’s data processing practices.
Security
Defense-in-depth, from infrastructure to operations
Certified security management, secure data processing and defined SLAs help protect the integrity, confidentiality and availability of customer data.
01
ISO 9001/IEC 27001/SOC I & II Certified
Independently audited annually, with full re-certification every three years. Covers access controls, incident handling, change management and continuous monitoring.
01
Continuous Vulnerability Scanning and Remediation (CVE)
DigitalRoute continuously scans products and dependencies for CVEs, prioritizes remediation by severity and impact, and provides vulnerability reports for supported releases.
01
Application & Infrastructure Security
UsageCloud™ runs on AWS with multi-AZ high availability and containerized workloads, built to handle complex usage data at scale while meeting regulatory standards.
01
Identity, Access & Operations
Production access is restricted to authorized personnel. Incidents are classified as critical, major or minor with defined response times. Uptime is reported quarterly.
01
Secure Development
Built on Kubernetes with modern DevOps practices. Regular product updates are published for UsageCloud™ and UsageCloud™ Private.
01
Incident Detection & Response
SLA defines availability monitoring at one-minute granularity with a target 1-hour response for critical incidents. Service credits apply if minimums are not met as set out in the applicable service level agreement. Status at status.digitalroute.io.
01
Finance-Grade Data Processing
UsageCloud™ and MediationZone™ are purpose-built for revenue-impacting data, ensuring that every event is fully auditable, secure and compliant at any volume.
Privacy & Data Protection
Privacy controls built into every data flow
Personal data is processed in accordance with applicable privacy laws and supported by defined policies and technical controls.
Privacy Policy & Contact
Our Cookie Policy and Data Privacy Policy explain how personal data is collected, used, shared, retained and protected. Please contact us at dpo@digitalroute.com if you have any questions regarding these policies.
Legal Bases, Rights & Transparency
Personal data is processed on lawful grounds and individuals may exercise their privacy rights in accordance with those laws.
Data Minimization & Anonymization
Customer data can be masked, de-identified or anonymized before storage, analysis or sharing.
Retention, Deletion & Lifecycle
Data retention and deletion practices are designed to support customer governance and regulatory requirements.
Compliance & Certifications
Independently audited. Every year.
Our security and quality practices are validated by independent third-party auditors. These certifications cover both DigitalRoute as an organization and specific cloud services, including Usage Engine Cloud Edition™ and UsageCloud™.
| Certification | Scope | Achieved | Audit Cycle | Status |
| ISO/IEC 27001 Information Security Management | DigitalRoute organization | 2018 | Annual surveillance; full re-cert every 3 years | Current |
| ISO 9001 Quality Management System | DigitalRoute organization | 2020 | Annual audit | Current |
| SOC 2 Type II Security, Availability & Confidentiality | UsageCloud™ | January 2021 | 12-month period, independent auditors | Current |
| SOC 1 Type II Internal Controls over Financial Reporting | UsageCloud™ | January 2025 | 12-month period, independent auditors | Current |
Access to Audit Reports
SOC and ISO reports are shared under NDA via your DigitalRoute representative or account team.
Email info@digitalroute.com to request access
Continuous Vulnerability Scanning and Remediation (CVE)
DigitalRoute continuously scans its products and dependencies for known vulnerabilities (CVEs) using OWASP-based software composition analysis built into our build pipelines. Findings are triaged by severity and product impact, with critical issues remediated with the same urgency as customer-reported defects. Vulnerability reports and impact analyses are available to customers on supported releases.
Availability & Status
High availability, with nowhere to hide
Formal SLAs, quarterly reporting and a public status page give full transparency on uptime, maintenance and incidents.
99.9%
SLA availability target
Measured with one-minute granularity, reported quarterly. Service credits apply if availability falls below the agreed minimum as set out in the applicable service level agreement.
SLA
Availability is defined as the percentage of time the service can execute scheduled business processes. Incidents are classified as critical, major or minor, each with defined reaction times, including a 1-hour target for critical incidents. Performance data is reported quarterly.
Live Status Page
View current status, scheduled maintenance and incident history at status.digitalroute.io. The Support Portal is available 24/7.
Subprocessors & Data Locations
Infrastructure you can trust
Customers are provided with information about hosting environments, data locations, security responsibilities and controls through formal documentation.
Amazon Web Services
UsageCloud™ and UsageCloud Private Edition run on AWS using Amazon EKS and AWS Fargate, with high availability across multiple Availability Zones.
Deployment Models
UsageCloud™ is available as SaaS. UsageCloud Private Edition can be deployed in your own cloud (AWS, GoogleCloud, Azure, OCI) or on premises.
Sub-processor Details
Sub-processor details are listed in our Data Processing Agreement available on InfoZone.
Resources & Documents
Everything security, legal and procurement need, in one place
Policies, SLAs and technical documents for security, procurement and legal teams.
Core Policies & Legal Documents
01
Data Privacy Policy & Cookie Policy
Information on personal data processing, privacy rights, cookies and contact details.
01
Cloud Service SLA & Support Service Descriptions
Available on InfoZone or request
from your DigitalRoute representative
01
Cloud Service Descriptions
Service and Functional Description describing the service made available by DigitalRoute as part of its UsageCloud.
01
Enterprise Subscription Agreement
Contractual documents referenced from the UsageCloud documentation
Security & Compliance Artifacts
01
ISO/IEC 27001 Certificate
Information security management— DigitalRoute organization
01
ISO 9001 Certificate
Quality management system — DigitalRoute organization
01
SOC 1 Type II & SOC 2 Type II Reports
UsageCloud™ — available on request under NDA
Product & Platform CONTENT
01
Security & Compliance Overview
Certifications for UsageCloud™ and our audit process
01
AWS Partnership & Architecture Resources
UsageCloud on AWS — whitepapers and technical blogs
01
User Documentation
UsageCloud™ and UsageCloud Private Edition — architecture, APIs and operational guidelines
Disclaimer
The information on this Trust Centre is provided for general informational purposes only and does not form part of, modify, or supersede any contract between you and DigitalRoute. Service availability targets, service level commitments, service credits, certifications and other details described here are summaries. The binding terms – including availability definitions, measurement methods, exclusions, reaction and resolution targets, and service credit entitlements – are set out solely in the applicable agreement.
Certifications and audit reports reflect their status as of their respective audit dates and are subject to their stated scope and audit cycles. DigitalRoute may update, supplement or remove information on this page at any time without notice. In the event of any conflict between this page and a signed agreement, the signed agreement prevails.
FAQ
Common questions from security and procurement
Direct answers for security, privacy and procurement teams.
Yes. DigitalRoute holds ISO/IEC 27001 (since 2018) and ISO 9001 (since 2020). UsageCloud™ is SOC 2 Type II certified since 2021 and SOC 1 Type II certified since January 2025, each with annual audit cycles.
View current status, scheduled maintenance and incident history at status.digitalroute.io.
Our SLA targets 99.9% availability per quarter, measured with one-minute granularity. Service credits apply as set out in the applicable service level agreement if availability falls below the agreed minimum.
We process personal data in accordance with applicable privacy laws. For more information, please see our Data Privacy Policy or contact us at dpo@digitalroute.com.
UsageCloud™ run on AWS with multi-AZ high availability. Specific regions are defined in customer agreements.
Reports are shared under NDA via your DigitalRoute representative. Contact them directly or reach out to info@digitalroute.com to request access.
Updates & Announcements
Our ongoing investment in trust
Key security, compliance and platform milestones.

- JULY 2025
- UsageCloud™ available on AWS Marketplace.
- JANUARY 2025
- UsageCloud™ achieves SOC 1 Type II certification.
JANUARY 2021
UsageCloud™ achieves SOC 2 Type II certification.
JANUARY 2021
UsageCloud™ launches on Amazon Web Services. - 2020
- ISO 9001 certification achieved.
2018
ISO/IEC 27001 certification achieved.
Contact & Reporting
Reach the right team, fast
Dedicated contacts for security, privacy and operational questions.
Security & Compliance Questions
Security, compliance and general trust-related questions
Customer Support Portal (24/7)
Report incidents and raise support requests through the Support Portal, available 24/7.
Contact your account team to arrange access
Need a document or a call with our support team?
SOC reports, ISO certificates and DPA agreements available on request.