Skip to content
BOOKING Q3 2026 · 2 OF 4 SLOTS OPEN · NEXT REVIEW WEDQ3 · 2/4 SLOTS · NEXT REV WED
Drop a brief
SECURITY/COMPLIANCE·DATA, ACCESS, INCIDENTPROCUREMENT-READY ↓

Built on infrastructure procurement can approve.

★ HONEST POSTURE

AAL is a small studio. We don’t have ISO 27001 yet. We do have GDPR-compliant practices, EU-region hosting, DPA-ready paperwork, and an honest security roadmap. This page is what we can actually commit to today.

01

Data handling.

GDPR-compliant by default. Lawful basis documented per engagement. Data-processing records maintained.

DPA ready. Standard DPA template sent within 24h of request. Custom DPA negotiable for enterprise engagements.

Subprocessor list published. Vercel (hosting), Sanity (CMS), Anthropic (AI), Airtable (operational). Updated on change.

Data minimization. We only collect what's needed to deliver the engagement. No behavioral tracking in audits or the journal.

02

Infrastructure.

EU-region hosting. Vercel edge in Frankfurt (FRA1) / Dublin (DUB1) by default. Client data never leaves EU unless explicitly scoped otherwise.

Encryption in transit + at rest. TLS 1.3 everywhere, AES-256 at rest via provider defaults.

Backups. Daily snapshots of CMS and operational data, 30-day retention, point-in-time restore available.

Monitoring. Error, uptime, and performance monitoring via Sentry + Vercel Speed Insights. On-call rotation for production incidents.

03

Access.

SSO-ready. Every client surface we ship supports SSO via Okta, Auth0, or custom SAML on request.

RBAC. Role-based access control baked into every CMS and internal tool we ship. Principle of least privilege by default.

Audit logs. All content and configuration changes logged. 90-day retention standard, longer on request.

Offboarding. Credentials rotated, access revoked, data handed over within 5 business days of engagement end.

04 · HONEST

Certifications roadmap.

ISO 27001, not certified today. Target: begin formal process Q1 2027.

SOC 2 Type II, not certified today. Target: 2027 after ISO 27001.

Annual penetration test, independent third-party review of client-facing surfaces. Next: Q3 2026.

GDPR compliance, active. Data Protection Impact Assessment (DPIA) performed per engagement as needed.

05

Incident response.

P0 (production down): initial acknowledgment within 1 hour. Active investigation within 4 hours.

P1 (data incident): client notified within 24 hours of detection. GDPR 72-hour reporting honored.

Post-mortems: written, shared with affected clients, and incorporated into runbooks.

06 · DOWNLOADS

Send these to procurement.

UPDATED: 2026-04
PDF · 3 PAGES

Standard DPA

GDPR-compliant data processing agreement template. Customisable under request.

PDF · 4 PAGES

Subprocessor list

Current vendors, data scope per vendor, hosting region. Updated on change.

PDF · 8 PAGES

Security whitepaper

Full picture doc combining this page into a procurement-ready PDF.

07 · TALK TO PROCUREMENT

Talk to procurement, not sales.

If procurement has specific requirements we haven’t surfaced here, tell us. We respond within 48 hours with what we can honestly commit to.

RESPONSE SLA48 hours
EU HOSTINGFRA1/DUB1