Security & Trust Center

ISO 27001 certified. EU-hosted. Audit-ready.

Everything your security, legal and procurement teams need to approve Springcast, certifications, EEA data residency, DPA and sub-processor transparency, in one place.

ISO/IEC 27001:2022, certified by Brand Compliance, RvA accreditation C 548

Trusted by 2,000+ customers and accounts · EEA-hosted · ISO 27001 certified · Full DPA available

AllianzAXAKPMGDAFEuropees ParlementEuropol
Certifications & documents

Certifications and documents in one place

ISO/IEC 27001:2022

Independently certified by Brand Compliance under RvA accreditation (C 548). Our information security management system is audited every year.

Request certificate details →

EEA data hosting

All processing takes place within the European Economic Area. Our applications run in the Netherlands, Germany and Finland. Audio, video and artwork are delivered through a CDN in the Netherlands, statistics are processed in the Netherlands, and backups are held in the Netherlands and Germany. No transfer to the US for core platform functionality.

See data residency →

GDPR Article 28 DPA

A full Data Processing Agreement is included, not bolted on. Signed before you publish a single episode.

Download the DPA →

Sub-processor transparency

A public, up-to-date register of every sub-processor that touches your data.

Download the register →

EcoVadis Gold

Awarded the EcoVadis Gold medal for sustainable, responsible business practices.

About our rating →

Terms (NLdigital)

Standard terms based on the NLdigital framework, widely accepted by Dutch and EU procurement teams.

Download the terms →

Security

Security by design, not by afterthought.

Compliance certifications confirm a security framework exists. Here is the framework, the controls behind the badge.

  • ISO 27001:2022 certified information security management system
  • Encryption in transit (TLS 1.2/1.3)
  • Backups encrypted at rest
  • Periodic authenticated automated penetration testing (OWASP Top Ten)
  • Incident response tested annually · breach notification < 72h
  • Single sign-on (SSO) and role-based access controls
  • All processing within the EEA
30,000+

episodes published every year on Springcast.

2,000+

customers and accounts trust Springcast with compliance-sensitive podcast data.

100%

of processing takes place within the EEA.

Frequently asked

Questions your security team will ask

Yes, ISO/IEC 27001:2022, independently certified by Brand Compliance under RvA accreditation (C 548). The certificate is reviewed every year; you can request a copy from our team.
All processing takes place within the European Economic Area. Our applications run in the Netherlands, Germany and Finland. Audio, video and artwork are delivered through a CDN in the Netherlands, statistics are processed in the Netherlands, and backups are held in the Netherlands and Germany. No podcast data is transferred to the US for core platform functionality.
Yes. A full GDPR Article 28 DPA is included and can be signed before you publish. A standard DPA is available to download.
Yes, we maintain a public, up-to-date sub-processor register, available as a downloadable PDF.
Yes. EU-hosted, GDPR Article 28 data processing, privacy by design and full data-subject support.
Contact our compliance team. We provide the ISO 27001 certificate, audit pack, DPA and sub-processor overview for procurement and security reviews.

Bring Springcast through your next security review.

Get the ISO 27001 certificate, audit pack, DPA and sub-processor overview from our team.