Monitoring
Compliance
SOC 2
In progress | Service Organization Controls (SOC 2) (Type II) trust services principles
GDPR
In progress | Protect the personal data and privacy of EU citizens for transactions that occur within EU member states
Subprocessors
AWS
Cloud computing and infrastructure services.
Adobe
Creative software suite for design, video, and documents.
Airtable
Visual database and spreadsheet hybrid tool.
Anthropic
AI company (creators of Claude large language models).
AssemblyAI
AI-powered speech-to-text API.
Bubble
No-code platform for building web applications.
Cloudflare
Web infrastructure, security, and DNS provider.
Customer.io
Automated email marketing platform.
Dashlane
Password management tool.
Subscribe to Updates
To gain access to our restricted compliance policies or subscribe to updates:
Please click the "Request all documents" button in the Resources section immediately below and accept the standard clickwrap NDA.
Then you will be granted access to our documentation and automatically subscribed to receive email notifications for any future changes to our Resources or authorized Subprocessors.
Resources
Privacy Policy
Details on how we collect and use information
Terms of Service
Storysnap's terms for its website.
Main Services Agreement
Agreement setting the terms between Storysnap and its clients.
Information Security Policy
Core governance policy detailing organizational security baselines, logical access controls, and cloud architecture responsibilities.
Data Retention & Disposal Policy
Guidelines for the secure retention, lifecycle management, and logical disposal of Client Assets in accordance with GDPR Processor obligations.
Business Continuity & Disaster Recovery
Executive overview of Storysnap’s cloud-native BCDR strategy, detailing our recovery objectives (RPO/RTO), data redundancy measures, and vendor infrastructure carve-outs in alignment with SOC 2 CC7.5.
Security Incident Response Plan
High-level summary of Storysnap’s Incident Response lifecycle, detailing our Security Response Team (SRT) operations, containment procedures, and statutory breach notification SLAs under GDPR Article 33.
