Skip to content

TRUST CENTER

One place for security, compliance and privacy.

Everything security, legal and procurement teams need to evaluate, approve and monitor DigitalRoute’s data processing practices.

Security

Defense-in-depth, from infrastructure to operations

Certified security management, secure data processing and defined SLAs help protect the integrity, confidentiality and availability of customer data.

01

ISO 9001/IEC 27001/SOC I & II Certified

Independently audited annually, with full re-certification every three years. Covers access controls, incident handling, change management and continuous monitoring.

01

Continuous Vulnerability Scanning and Remediation (CVE)

DigitalRoute continuously scans products and dependencies for CVEs, prioritizes remediation by severity and impact, and provides vulnerability reports for supported releases.

01

Application & Infrastructure Security

UsageCloud™ runs on AWS with multi-AZ high availability and containerized workloads, built to handle complex usage data at scale while meeting regulatory standards.

01

Identity, Access & Operations

Production access is restricted to authorized personnel. Incidents are classified as critical, major or minor with defined response times. Uptime is reported quarterly.

01

Secure Development

Built on Kubernetes with modern DevOps practices. Regular product updates are published for UsageCloud™ and UsageCloud™ Private.

01

Incident Detection & Response

SLA defines availability monitoring at one-minute granularity with a target 1-hour response for critical incidents. Service credits apply if minimums are not met as set out in the applicable service level agreement. Status at status.digitalroute.io.

01

Finance-Grade Data Processing

UsageCloud™ and MediationZone™ are purpose-built for revenue-impacting data, ensuring that every event is fully auditable, secure and compliant at any volume.

Privacy & Data Protection

Privacy controls built into every data flow

Personal data is processed in accordance with applicable privacy laws and supported by defined policies and technical controls.

Privacy Policy & Contact

Our Cookie Policy and Data Privacy Policy explain how personal data is collected, used, shared, retained and protected. Please contact us at dpo@digitalroute.com if you have any questions regarding these policies.

Legal Bases, Rights & Transparency

Personal data is processed on lawful grounds and individuals may exercise their privacy rights in accordance with those laws.

Data Minimization & Anonymization

Customer data can be masked, de-identified or anonymized before storage, analysis or sharing.


Retention, Deletion & Lifecycle

Data retention and deletion practices are designed to support customer governance and regulatory requirements.

Compliance & Certifications

Independently audited. Every year.

Our security and quality practices are validated by independent third-party auditors. These certifications cover both DigitalRoute as an organization and specific cloud services, including Usage Engine Cloud Edition™ and UsageCloud™.

CertificationScopeAchievedAudit CycleStatus
ISO/IEC 27001
Information Security Management
DigitalRoute organization2018Annual surveillance; full re-cert every 3 yearsCurrent
ISO 9001
Quality Management System
DigitalRoute organization2020Annual auditCurrent
SOC 2 Type II
Security, Availability & Confidentiality
UsageCloud™January 202112-month period, independent auditorsCurrent
SOC 1 Type II
Internal Controls over Financial Reporting
UsageCloud™January 202512-month period, independent auditorsCurrent

Access to Audit Reports

SOC and ISO reports are shared under NDA via your DigitalRoute representative or account team. 
Email info@digitalroute.com to request access

Continuous Vulnerability Scanning and Remediation (CVE)

DigitalRoute continuously scans its products and dependencies for known vulnerabilities (CVEs) using OWASP-based software composition analysis built into our build pipelines. Findings are triaged by severity and product impact, with critical issues remediated with the same urgency as customer-reported defects. Vulnerability reports and impact analyses are available to customers on supported releases.

Availability & Status

High availability, with nowhere to hide

Formal SLAs, quarterly reporting and a public status page give full transparency on uptime, maintenance and incidents.

99.9%

SLA availability target

Measured with one-minute granularity, reported quarterly. Service credits apply if availability falls below the agreed minimum as set out in the applicable service level agreement.


SLA

Availability is defined as the percentage of time the service can execute scheduled business processes. Incidents are classified as critical, major or minor, each with defined reaction times, including a 1-hour target for critical incidents. Performance data is reported quarterly.


Live Status Page

View current status, scheduled maintenance and incident history at status.digitalroute.io. The Support Portal is available 24/7.

View status page →

Subprocessors & Data Locations

Infrastructure you can trust

Customers are provided with information about hosting environments, data locations, security responsibilities and controls through formal documentation.

Amazon Web Services

UsageCloud™ and UsageCloud Private Edition run on AWS using Amazon EKS and AWS Fargate, with high availability across multiple Availability Zones.

Deployment Models

UsageCloud™ is available as SaaS. UsageCloud Private Edition can be deployed in your own cloud (AWS, GoogleCloud, Azure, OCI) or on premises.

Sub-processor Details

Sub-processor details are listed in our Data Processing Agreement available on InfoZone.

Resources & Documents

Everything security, legal and procurement need, in one place

Policies, SLAs and technical documents for security, procurement and legal teams.



Core Policies & Legal Documents

01

Data Privacy Policy & Cookie Policy

 Information on personal data processing, privacy rights, cookies and contact details.

01

Cloud Service SLA & Support Service Descriptions

Available on InfoZone or request 
from your DigitalRoute representative 

01

Cloud Service Descriptions

Service and Functional Description describing the service made available by DigitalRoute as part of its UsageCloud.

01

Enterprise Subscription Agreement

Contractual documents referenced from the UsageCloud documentation

Security & Compliance Artifacts 

01

ISO/IEC 27001 Certificate

Information security management— DigitalRoute organization

01

ISO 9001 Certificate

Quality management system — DigitalRoute organization

01

SOC 1 Type II & SOC 2 Type II Reports

UsageCloud™ — available on request under NDA


Product & Platform CONTENT

01

Security & Compliance Overview

Certifications for UsageCloud™ and our audit process

01

AWS Partnership & Architecture Resources

UsageCloud on AWS — whitepapers and technical blogs

01

User Documentation

UsageCloud™ and UsageCloud Private Edition — architecture, APIs and operational guidelines

Disclaimer

The information on this Trust Centre is provided for general informational purposes only and does not form part of, modify, or supersede any contract between you and DigitalRoute. Service availability targets, service level commitments, service credits, certifications and other details described here are summaries. The binding terms – including availability definitions, measurement methods, exclusions, reaction and resolution targets, and service credit entitlements – are set out solely in the applicable agreement.

Certifications and audit reports reflect their status as of their respective audit dates and are subject to their stated scope and audit cycles. DigitalRoute may update, supplement or remove information on this page at any time without notice. In the event of any conflict between this page and a signed agreement, the signed agreement prevails.

FAQ

Common questions from security and procurement

Direct answers for security, privacy and procurement teams.

Yes. DigitalRoute holds ISO/IEC 27001 (since 2018) and ISO 9001 (since 2020). UsageCloud™ is SOC 2 Type II certified since 2021 and SOC 1 Type II certified since January 2025, each with annual audit cycles.

View current status, scheduled maintenance and incident history at status.digitalroute.io.

Our SLA targets 99.9% availability per quarter, measured with one-minute granularity. Service credits apply as set out in the applicable service level agreement if availability falls below the agreed minimum.

We process personal data in accordance with applicable privacy laws. For more information, please see our Data Privacy Policy or contact us at dpo@digitalroute.com.

UsageCloud™ run on AWS with multi-AZ high availability. Specific regions are defined in customer agreements.

Reports are shared under NDA via your DigitalRoute representative. Contact them directly or reach out to info@digitalroute.com to request access.

Updates & Announcements

Our ongoing investment in trust

Key security, compliance and platform milestones.

  • JULY 2025
  • UsageCloud™ available on AWS Marketplace.
  • JANUARY 2025
  • UsageCloud™ achieves SOC 1 Type II certification.

    JANUARY 2021
    UsageCloud™ achieves SOC 2 Type II certification.

    JANUARY 2021
    UsageCloud™ launches on Amazon Web Services.
  • 2020
  • ISO 9001 certification achieved.

    2018
    ISO/IEC 27001 certification achieved.



Contact & Reporting

Reach the right team, fast

Dedicated contacts for security, privacy and operational questions.

Security & Compliance Questions

Security, compliance and general trust-related questions

info@digitalroute.com

Data Protection

Personal data, regulatory rights and privacy practices.

dpo@digitalroute.com

Customer Support Portal (24/7)

Report incidents and raise support requests through the Support Portal, available 24/7.

Contact your account team to arrange access

Need a document or a call with our support team?

SOC reports, ISO certificates and DPA agreements available on request.