Trust Center

    Security, compliance and transparency at Maat Impact

    Certifications and compliance

    Maat Impact aligns its security program with recognized international frameworks.

    Current status

    • GDPR and LOPDGDD compliance (AES-256-GCM encryption, data subject rights, data retention)
    • Alignment with OWASP Top 10 and OWASP ASVS
    • Continuous auditing with 19 security quality gates in CI/CD

    Roadmap

    • ISO/IEC 27001 certification (in preparation)
    • National Security Framework (ENS) and SOC 2 Type II (assessment)

    Data Processing Agreement (DPA)

    We provide our customers with a Data Processing Agreement (DPA) in accordance with Article 28 of the GDPR. The document is made available under a non-disclosure agreement (NDA).

    Request DPA

    Subprocessors

    We maintain a public and up-to-date list of the subprocessors involved in delivering our services.

    View subprocessors list

    Security policy

    Information security is a fundamental pillar of the platform by design (security by design).

    • Encryption in transit (TLS 1.2+) and at rest (AES-256-GCM)
    • Multi-factor authentication (MFA) and role-based access control (RBAC)
    • Real-time breach detection and audit trail with HMAC-SHA256 integrity

    See our vulnerability disclosure policy (security.txt)

    Security contact

    To report a vulnerability or for security and privacy inquiries:

    Security: security@maatimpact.com

    Data Protection Officer (DPO): dpo@maatimpact.com