Skip to content
Ditap®
Trust Center

Trust, in detail — not in a badge

How we protect the data we handle, how we run our clients' infrastructure, and what commitments we hold in writing. No invented certifications.

Verifiable right now

We don't hold a third-party certification yet, and we won't display a seal we haven't earned. What we can do is publish the actual posture and tell you how to check each point yourself, without asking us for anything.

HTTPS enforced site-wide

HSTS with includeSubDomains and preload: the browser refuses to connect over HTTP even before the first visit.

How to check it: Check the Strict-Transport-Security header in developer tools, or the domain on hstspreload.org.

We never touch card data

Payment happens on Stripe and MercadoPago. No card number passes through our servers or lands in our logs.

How to check it: At checkout the URL switches to the gateway's domain. The card form is never on ditap.io.

Analytics denied by default

Google Consent Mode v2 starts fully denied, with ads data redaction on. Until you accept, no measurement cookie is written.

How to check it: Open the site in a private window and inspect cookies before touching the banner: there is no _ga.

Error data hosted in the EU

Error monitoring uses the European data residency, in Germany. No transfer outside the EEA for that processing.

How to check it: It's declared in full on the sub-processors page.

Complete security headers

Content-Security-Policy, X-Frame-Options set to DENY, nosniff, Referrer-Policy, and Permissions-Policy blocking camera, microphone and geolocation.

How to check it: Paste ditap.io into securityheaders.com and read the result.

One-click unsubscribe on every send

Emails carry List-Unsubscribe with one-click POST (RFC 8058): opting out is immediate and doesn't depend on someone processing it by hand.

How to check it: In Gmail, the unsubscribe button appears next to the sender.

GDPR — Reglamento (UE) 2016/679

Active compliance program

ISO/IEC 27001

Alignment in progress — certification not yet obtained

NIS2 — Directiva (UE) 2022/2555

Directive relevant to our clients — DITAP supports compliance

3 SLA tiers · 9 sub-processors — See compliance in detail

Security FAQ

Is DITAP ISO 27001 or SOC 2 certified?

Not yet. We align with ISO 27001's control domains and operate with that discipline, but we don't hold a third-party certification — and we won't claim we do. Detail at /trust/compliance.

Where is DITAP's site and product data hosted?

It depends on the vendor: hosting on Vercel, database on Supabase, DNS on Cloudflare, payments on Stripe/MercadoPago. Full detail, with data location per vendor, at /trust/sub-processors.

How do I report a security vulnerability?

Through our responsible disclosure policy at /security/disclosure, with a direct contact channel and a committed response timeframe.

What happens if DITAP misses an SLA response time?

Each managed-service tier defines a service credit for missed response times, detailed at /trust/sla. The signed contract with each client takes precedence over this public page.

Need security documentation for your procurement process?

Security questionnaires, a DPA draft, or the technical detail of a specific project — write to us and we'll coordinate it.

Email [email protected]