Trust and security
How DGTL handles security, data, and contracts.
Dated, factual, scannable. Built to pass enterprise procurement and legal review without a multi-week redline cycle. Request any document directly from the lines below, or email security@withdgtl.com for vulnerability disclosures and security questions.
Last reviewed 2026-08-18
Compliance status
Frameworks DGTL currently supports, is working toward, or plans to adopt.
- SOC 2 Type ILive
Attestation issued. Continuous compliance monitoring via Vanta. Report available on request under NDA.
Updated 2026-08-18
- SOC 2 Type IIIn progress
Observation window underway. Type II report expected following the standard audit cycle.
Updated 2026-08-18
- ISO 27001Planned
Certification targeted Q1 2027. Controls are being implemented in parallel with the SOC 2 program to minimize duplicate work.
Updated 2026-08-18
- GDPR and LOPDP complianceLive
Data Processing Agreement with Standard Contractual Clauses in place for EU and UK data transfers. Ecuador's LOPDP law applies to DGTL as a local processor. Breach notification SLA of 72 hours from awareness.
Updated 2026-08-18
- LATAM data privacy frameworksLive
LGPD (Brazil), Ley 1581 (Colombia), LFPDPPP (Mexico), and Ley 21719 (Chile) support documented in the DPA. Regional data residency available on request.
Updated 2026-08-18
Data handling
How client data is stored, encrypted, accessed, and backed up.
- Data residencyLive
Defaults to US-region hosting (AWS us-east-1 or GCP us-central1) for North American clients and EU-region hosting (AWS eu-west-1 or GCP europe-west1) for European clients. LATAM clients can choose either, or a LATAM-local region when available.
Updated 2026-08-18
- Encryption in transitLive
TLS 1.3 minimum on every endpoint. HSTS enforced with preload. Plaintext HTTP returns a 301 to HTTPS at the edge.
Updated 2026-08-18
- Encryption at restLive
AES-256 at rest on all production data stores. Customer-managed keys available for enterprise engagements on request.
Updated 2026-08-18
- Access managementLive
Role-based access, MFA enforced on every production system, quarterly access reviews, time-boxed credentials for production data access.
Updated 2026-08-18
- Backups and recoveryLive
Automated daily backups with 30-day retention. Cross-region replication for production databases. Quarterly restore exercises.
Updated 2026-08-18
Security program
Operational security practices and the DGTL engineering SDLC.
- Security headersLive
HSTS with preload, X-Frame-Options DENY, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, COOP, and CORP are live today, with an A grade on every securityheaders.com directive except script-src. There, Next.js static rendering forces a documented compromise: nonce-based CSP is not viable on this build shape, so script-src ships a hardened inline policy while third-party scripts stay consent-gated. We publish the trade-off instead of hiding it.
Updated 2026-08-18
- Dependency managementLive
Automated dependency scanning via GitHub Dependabot plus weekly human review. Critical CVEs patched within 24 hours. Non-critical within one sprint.
Updated 2026-08-18
- Incident responseLive
Documented runbook with 24-hour initial notification SLA to affected clients. Quarterly tabletop exercises with the on-call rotation. Post-incident reports shared with affected clients within 7 business days.
Updated 2026-08-18
- Secure SDLCLive
Threat modeling at the start of every engagement, code review required on every pull request, automated SAST in CI, manual security review before production release.
Updated 2026-08-18
- Vulnerability disclosureLive
Security researchers can report vulnerabilities to security@withdgtl.com. We acknowledge within 48 hours and coordinate disclosure. No bounty program yet; recognition published on request.
Updated 2026-08-18
Contracts and insurance
Standard legal documents and coverage. Request any of the items below and a practice lead will send within 48 hours.
- Master Services AgreementLive
- Request
Standard MSA covering scope, deliverables, payment terms, IP ownership, confidentiality, and termination. Most mid-market clients sign without redlines. Enterprise riders accommodated within one week.
Updated 2026-08-18
- Data Processing AgreementLive
- Request
GDPR, LOPDP, and LATAM-framework-aligned DPA. Includes Standard Contractual Clauses for EU and UK transfers, breach notification windows, and subprocessor disclosure obligations.
Updated 2026-08-18
- Mutual Non-Disclosure AgreementLive
- Request
Two-way NDA signed before Discovery begins. Covers confidentiality, non-solicitation, and standard exclusions.
Updated 2026-08-18
- Professional liability insuranceAvailable on request
- Request
Errors and omissions coverage sized to engagement scope. Additional insured riders available for enterprise clients. Certificate of insurance issued within 48 hours of request.
Updated 2026-08-18
- Cyber liability insuranceAvailable on request
- Request
First and third party coverage including breach response, notification costs, and regulatory defense. Limits scaled to engagement sensitivity.
Updated 2026-08-18
- Subprocessor listAvailable on request
- Request
Current subprocessors (hosting, email, monitoring, analytics, CRM) listed with region, purpose, and DPA status. Updates communicated via email 30 days before new subprocessors are added.
Updated 2026-08-18
Reports and questionnaires
Assessments and response libraries available to enterprise buyers on request.
- VPAT 2.5 Accessibility Conformance ReportIn progress
- Request
DGTL targets WCAG 2.2 Level AA conformance. A Voluntary Product Accessibility Template documenting conformance status will be available on request once the VPAT draft completes. See /accessibility for the current statement, known issues, and feedback mechanism.
Updated 2026-08-18
- Security questionnaire response libraryLive
- Request
Pre-built responses for SIG Core, CAIQ, VSAQ, and SOC 2 vendor questionnaires. Completed responses returned within 5 business days for standard formats, 7 to 10 days for custom questionnaires.
Updated 2026-08-18
Security contact
Report a vulnerability, ask a security question, or request a document. DGTL acknowledges security reports within 48 hours.
- Security contact:
- security@withdgtl.com
- General contact:
- hello@withdgtl.com
- Headquarters:
- Quito, Ecuador. Delivery teams distributed across the Americas.
See also: Accessibility statement, Who we serve, Privacy policy.