Security

Last reviewed: 18 August 2026

You are evaluating a compliance product, so you will check these claims rather than take them on trust. This page states what is actually in place, names the third parties that touch your data, and is explicit about what we do not yet have. Anything on this page can be verified, and where we are not certified we say so rather than implying otherwise.

The Art of Service Pty Ltd (ABN 19 095 825 308) is an Australian company based in Queensland. The Platform is operated by a small team, which is why this page favours plain description over a certification wall.

What we are not, stated plainly

  • We are not SOC 2 or ISO 27001 certified. We hold no third party attestation of our own controls. If your procurement process requires one, we will not pass it today.
  • We do not run our own multi-factor authentication. Accounts that sign in with Google or Microsoft inherit whatever MFA your identity provider enforces, which for most organisations is the stronger arrangement. Accounts using a password have no second factor.
  • Backups are held in one region. Daily database snapshots are retained for seven days on the same provider as the primary database. There is no second-region copy today.
  • We have not commissioned an external penetration test.

We publish this because a compliance vendor that overstates its own posture is the worst kind. If any of the above is a blocker for your organisation, tell us at support@theartofservice.com and we will tell you honestly whether and when it is likely to change.

Hosting and data residency

  • Database and API are hosted by Hetzner Online GmbH in Germany. The knowledge graph, your account, assessments and saved work all live there.
  • Frontend is served by Vercel from a global edge network. It handles page delivery only.
  • The company is Australian, so Australian law applies to us alongside the GDPR obligations set out in our Data Processing Agreement.

Encryption

  • In transit. All connections use TLS. Certificates are issued and renewed automatically through Let's Encrypt, terminated at Caddy in front of the API.
  • At rest. Data on our servers sits on encrypted volumes.
  • Transport hardening. The site is served with HSTS including subdomains and preload, plus X-Frame-Options: DENY and X-Content-Type-Options: nosniff. You can confirm this yourself with curl -I https://compliance.theartofservice.com.

Authentication and access

  • Single sign-on. You can sign in with Google or Microsoft. Where you do, account security, password policy and multi-factor enforcement stay with your identity provider rather than with us, so your existing controls apply unchanged.
  • Passwords. Accounts that do not use SSO are protected by a password and have no second factor. If MFA is a requirement for you, use Google or Microsoft sign-in.
  • API keys. Programmatic access uses bearer keys prefixed tas_, issued and revocable from your account settings. Treat them as secrets.

Backups and recovery

The graph database is dumped daily at 02:00 UTC and snapshots are retained for seven days. Restores are performed from those dumps. As noted above, copies are held in a single region.

Sub-processors

These are the third parties that may process data on our behalf. We give at least 30 days notice before adding a new one, as committed in the DPA.

Sub-processorPurposeData processedLocation
Hetzner Online GmbHBackend hosting: database, APIAll Platform dataGermany
Vercel Inc.Frontend hostingIP addresses, browser metadataGlobal edge network
Cerebras SystemsAI inference for advisory queriesQuery text, anonymised, not storedUnited States
Stripe Inc.Payment processingEmail, subscription statusUnited States
Twilio (SendGrid)Transactional emailName, email addressUnited States

Advisory queries sent to Cerebras for inference are not retained by us after the answer is returned.

Incident response

If we become aware of a personal data breach affecting you, we will notify you within 72 hours, including the nature of the breach, its likely effects, and the corrective measures taken. This is a contractual commitment in the DPA, not an aspiration.

Report a suspected vulnerability or incident to support@theartofservice.com. We will acknowledge within two business days. We do not currently run a paid bug bounty, and we will not pursue anyone who reports a genuine issue in good faith and gives us reasonable time to fix it.

Your data, and getting it back

  • Deletion. On request, or on termination, we delete personal data and your compliance data within 30 days and confirm in writing, except where law requires retention.
  • Export. Your assessments and saved work can be exported from the Platform.
  • We do not train models on your data. Advisory queries are used to answer that query.

Questionnaires and diligence

We respond to reasonable written security questionnaires within 30 days, as committed in the DPA. Send yours to support@theartofservice.com.

Related: Data Processing Agreement · Privacy Policy · Terms of Service