Skip to content

Trust and security

How DGTL handles security, data, and contracts.

Dated, factual, scannable. Built to pass enterprise procurement and legal review without a multi-week redline cycle. Request any document directly from the lines below, or email security@withdgtl.com for vulnerability disclosures and security questions.

Last reviewed 2026-08-18

Compliance status

Frameworks DGTL currently supports, is working toward, or plans to adopt.

SOC 2 Type ILive

Attestation issued. Continuous compliance monitoring via Vanta. Report available on request under NDA.

Updated 2026-08-18

SOC 2 Type IIIn progress

Observation window underway. Type II report expected following the standard audit cycle.

Updated 2026-08-18

ISO 27001Planned

Certification targeted Q1 2027. Controls are being implemented in parallel with the SOC 2 program to minimize duplicate work.

Updated 2026-08-18

GDPR and LOPDP complianceLive

Data Processing Agreement with Standard Contractual Clauses in place for EU and UK data transfers. Ecuador's LOPDP law applies to DGTL as a local processor. Breach notification SLA of 72 hours from awareness.

Updated 2026-08-18

LATAM data privacy frameworksLive

LGPD (Brazil), Ley 1581 (Colombia), LFPDPPP (Mexico), and Ley 21719 (Chile) support documented in the DPA. Regional data residency available on request.

Updated 2026-08-18

Data handling

How client data is stored, encrypted, accessed, and backed up.

Data residencyLive

Defaults to US-region hosting (AWS us-east-1 or GCP us-central1) for North American clients and EU-region hosting (AWS eu-west-1 or GCP europe-west1) for European clients. LATAM clients can choose either, or a LATAM-local region when available.

Updated 2026-08-18

Encryption in transitLive

TLS 1.3 minimum on every endpoint. HSTS enforced with preload. Plaintext HTTP returns a 301 to HTTPS at the edge.

Updated 2026-08-18

Encryption at restLive

AES-256 at rest on all production data stores. Customer-managed keys available for enterprise engagements on request.

Updated 2026-08-18

Access managementLive

Role-based access, MFA enforced on every production system, quarterly access reviews, time-boxed credentials for production data access.

Updated 2026-08-18

Backups and recoveryLive

Automated daily backups with 30-day retention. Cross-region replication for production databases. Quarterly restore exercises.

Updated 2026-08-18

Security program

Operational security practices and the DGTL engineering SDLC.

Security headersLive

HSTS with preload, X-Frame-Options DENY, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, COOP, and CORP are live today, with an A grade on every securityheaders.com directive except script-src. There, Next.js static rendering forces a documented compromise: nonce-based CSP is not viable on this build shape, so script-src ships a hardened inline policy while third-party scripts stay consent-gated. We publish the trade-off instead of hiding it.

Updated 2026-08-18

Dependency managementLive

Automated dependency scanning via GitHub Dependabot plus weekly human review. Critical CVEs patched within 24 hours. Non-critical within one sprint.

Updated 2026-08-18

Incident responseLive

Documented runbook with 24-hour initial notification SLA to affected clients. Quarterly tabletop exercises with the on-call rotation. Post-incident reports shared with affected clients within 7 business days.

Updated 2026-08-18

Secure SDLCLive

Threat modeling at the start of every engagement, code review required on every pull request, automated SAST in CI, manual security review before production release.

Updated 2026-08-18

Vulnerability disclosureLive

Security researchers can report vulnerabilities to security@withdgtl.com. We acknowledge within 48 hours and coordinate disclosure. No bounty program yet; recognition published on request.

Updated 2026-08-18

Contracts and insurance

Standard legal documents and coverage. Request any of the items below and a practice lead will send within 48 hours.

Master Services AgreementLive

Standard MSA covering scope, deliverables, payment terms, IP ownership, confidentiality, and termination. Most mid-market clients sign without redlines. Enterprise riders accommodated within one week.

Updated 2026-08-18

Request
Data Processing AgreementLive

GDPR, LOPDP, and LATAM-framework-aligned DPA. Includes Standard Contractual Clauses for EU and UK transfers, breach notification windows, and subprocessor disclosure obligations.

Updated 2026-08-18

Request
Mutual Non-Disclosure AgreementLive

Two-way NDA signed before Discovery begins. Covers confidentiality, non-solicitation, and standard exclusions.

Updated 2026-08-18

Request
Professional liability insuranceAvailable on request

Errors and omissions coverage sized to engagement scope. Additional insured riders available for enterprise clients. Certificate of insurance issued within 48 hours of request.

Updated 2026-08-18

Request
Cyber liability insuranceAvailable on request

First and third party coverage including breach response, notification costs, and regulatory defense. Limits scaled to engagement sensitivity.

Updated 2026-08-18

Request
Subprocessor listAvailable on request

Current subprocessors (hosting, email, monitoring, analytics, CRM) listed with region, purpose, and DPA status. Updates communicated via email 30 days before new subprocessors are added.

Updated 2026-08-18

Request

Reports and questionnaires

Assessments and response libraries available to enterprise buyers on request.

VPAT 2.5 Accessibility Conformance ReportIn progress

DGTL targets WCAG 2.2 Level AA conformance. A Voluntary Product Accessibility Template documenting conformance status will be available on request once the VPAT draft completes. See /accessibility for the current statement, known issues, and feedback mechanism.

Updated 2026-08-18

Request
Security questionnaire response libraryLive

Pre-built responses for SIG Core, CAIQ, VSAQ, and SOC 2 vendor questionnaires. Completed responses returned within 5 business days for standard formats, 7 to 10 days for custom questionnaires.

Updated 2026-08-18

Request

Security contact

Report a vulnerability, ask a security question, or request a document. DGTL acknowledges security reports within 48 hours.

Security contact:
security@withdgtl.com
General contact:
hello@withdgtl.com
Headquarters:
Quito, Ecuador. Delivery teams distributed across the Americas.

See also: Accessibility statement, Who we serve, Privacy policy.