Inly Trust Center
Core is where our customers run business-critical work — client records, operational data, financial flows. This is the public account of how the Core platform is secured: the controls we run, the providers we rely on, and where we stand on the standards our customers ask about.
Anything these pages don't answer goes to hello@inly.se.
Compliance
- ISO 27001In progress
- Actively pursuing the international standard for information security management.
- GDPRCompliant
- EU-based operations under the world's strictest standard for data privacy.
Resources
View allAgreements
- Data processing agreementon request
Documentation
Controls
View allInfrastructure security
- EU data residency maintained
- Point-in-time backups configured
- Data encryption at rest utilized
Access control
- Unique account authentication enforced
- Two-factor authentication required
- Single sign-on prioritized
Product security
- OWASP Top 10 applied
- Code review conducted
- Automated testing performed continuously
Internal security procedures
- Incident response procedures established
- Infrastructure monitoring implemented
- Application monitoring and alerting configured
Data and privacy
- Processing limited to agreed purposes
- Production data access minimized
- Data subject rights supported
Subprocessors
View details- Amazon Web ServicesData storageUnited States (EU infrastructure region)
- CloudflareCloud providerUnited States (global edge)
- Laravel CloudManaged application platformUnited States (EU infrastructure region)
- Laravel NightwatchMonitoringUnited States (EU infrastructure region)
- OpenAIAIUnited States
- ResendEmail deliveryUnited States (EU infrastructure region)
- TwilioSMS deliveryUnited States
Questions about security or privacy?
Two addresses, both read by people.
- Security
- Security questions, customer questionnaires, vulnerability reports.hello@inly.se
- Privacy
- DPA requests, data subject rights, anything GDPR.legal@inly.se