Security
Last reviewed: 18 August 2026
You are evaluating a compliance product, so you will check these claims rather than take them on trust. This page states what is actually in place, names the third parties that touch your data, and is explicit about what we do not yet have. Anything on this page can be verified, and where we are not certified we say so rather than implying otherwise.
The Art of Service Pty Ltd (ABN 19 095 825 308) is an Australian company based in Queensland. The Platform is operated by a small team, which is why this page favours plain description over a certification wall.
It is built and operated by Gerard Blokdyk, who has spent 25 years writing about compliance frameworks for practitioners. If anything on this page turns out to be wrong, it is wrong under his name. Tell us and it gets corrected.
What we are not, stated plainly
- We are not SOC 2 or ISO 27001 certified. We hold no third party attestation of our own controls. If your procurement process requires one, we will not pass it today.
- We do not run our own multi-factor authentication. Accounts that sign in with Google or Microsoft inherit whatever MFA your identity provider enforces, which for most organisations is the stronger arrangement. Accounts using a password have no second factor.
- Backups are held in one region. Daily database snapshots are retained for seven days on the same provider as the primary database. There is no second-region copy today.
- We have not commissioned an external penetration test.
Rather than leave it at “not certified”, we ran ourselves through our own product. Our position on all 93 ISO 27001 Annex A controls is published, including the fifteen we do not meet at all, each with the reason. No compliance vendor we compete with publishes theirs, and having written ours we understand why.
We publish this because a compliance vendor that overstates its own posture is the worst kind. If any of the above is a blocker for your organisation, tell us at support@theartofservice.com and we will tell you honestly whether and when it is likely to change.
Hosting and data residency
- Database and API are hosted by Hetzner Online GmbH in Germany. The knowledge graph, your account, assessments and saved work all live there.
- Frontend is served by Vercel from a global edge network. It handles page delivery only.
- The company is Australian, so Australian law applies to us alongside the GDPR obligations set out in our Data Processing Agreement.
Encryption
- In transit. All connections use TLS. Certificates are issued and renewed automatically through Let's Encrypt, terminated at Caddy in front of the API.
- At rest. Data on our servers sits on encrypted volumes.
- Transport hardening. The site is served with HSTS including subdomains and preload, plus
X-Frame-Options: DENYandX-Content-Type-Options: nosniff. You can confirm this yourself withcurl -I https://compliance.theartofservice.com.
Authentication and access
- Single sign-on. You can sign in with Google or Microsoft. Where you do, account security, password policy and multi-factor enforcement stay with your identity provider rather than with us, so your existing controls apply unchanged.
- Passwords. Accounts that do not use SSO are protected by a password and have no second factor. If MFA is a requirement for you, use Google or Microsoft sign-in.
- API keys. Programmatic access uses bearer keys prefixed
tas_, issued and revocable from your account settings. Treat them as secrets.
Account activity log
Every account carries a log of the actions taken on it: sign-ins, API keys issued and revoked, documents analysed, exports generated, self-assessments saved, team members invited, SSO configured. You can read it and export it as CSV from your account settings without asking us.
It records the fact of an action, never its content. That a document was analysed against ISO 27001, not the document. That a questionnaire was answered, not its answers. A log that copies the payload is a second, less guarded store of your confidential material, and we would rather not hold one.
The IP address on each entry is truncated to the network before it is stored, /24 on IPv4 and /48 on IPv6: enough to answer "was that me?", not enough to be a location history. Entries are deleted after 365 days. Logging started on 21 August 2026, so nothing before that date is in it, and we would rather show you an empty log than backfill one.
Persistent evidence, and what we keep of it
On the Professional tier you can hand the platform a document, a policy, a procedure, an existing audit report, and it works out which controls that document evidences. The judgement is kept. From then on any framework in the graph can be answered against your actual posture rather than in general, without paying to read the document again. The cost falls on the first framework. The six hundred and first is free.
Two kinds of coverage, and they are never merged. Direct means a document of yours was actually judged against that control. Inherited means a control you hold direct evidence for maps to it at high confidence, unrefuted, and a person judged that mapping. Inherited coverage is a lead, not a finding: it says your existing evidence probably covers this, go and check. Presenting a derived claim as an audited one is the failure this platform exists to avoid. A control nobody has assessed reads as unassessed, which is not a gap and is never counted as one.
We do not store your document. What is kept is its SHA-256 hash, its filename, and the excerpt behind each binding, capped at 400 characters. That excerpt is the citation that makes the claim checkable, and it is deliberately too short to reconstitute the file from our database. Holding whole customer policies would change this platform’s security obligations the day the first file arrived, and it would contradict the promise made directly above. Deleting a piece of evidence removes it and every binding derived from it.
Backups and recovery
The graph database is dumped daily at 02:00 UTC and snapshots are retained for seven days. Restores are performed from those dumps. As noted above, copies are held in a single region.
Sub-processors
These are the third parties that may process data on our behalf. We give at least 30 days notice before adding a new one, as committed in the DPA.
| Sub-processor | Purpose | Data processed | Location |
|---|---|---|---|
| Hetzner Online GmbH | Backend hosting: database, API | All Platform data | Germany |
| Vercel Inc. | Frontend hosting | IP addresses, browser metadata | Global edge network |
| Cerebras Systems | AI inference for advisory queries | Query text, anonymised, not stored | United States |
| Stripe Inc. | Payment processing | Email, subscription status | United States |
| Twilio (SendGrid) | Transactional email | Name, email address | United States |
Advisory queries sent to Cerebras for inference are not retained by us after the answer is returned.
Incident response
If we become aware of a personal data breach affecting you, we will notify you within 72 hours, including the nature of the breach, its likely effects, and the corrective measures taken. This is a contractual commitment in the DPA, not an aspiration.
Report a suspected vulnerability or incident to support@theartofservice.com. We will acknowledge within two business days. We do not currently run a paid bug bounty, and we will not pursue anyone who reports a genuine issue in good faith and gives us reasonable time to fix it.
Your data, and getting it back
- Deletion. On request, or on termination, we delete personal data and your compliance data within 30 days and confirm in writing, except where law requires retention.
- Export. Your assessments and saved work can be exported from the Platform.
- We do not train models on your data. Advisory queries are used to answer that query.
Questionnaires and diligence
We respond to reasonable written security questionnaires within 30 days, as committed in the DPA. Send yours to support@theartofservice.com.
Related: Data Processing Agreement · Privacy Policy · Terms of Service