Business Continuity
Data Privacy
HR security and governance
Incident Management
Infrastructure security
Product Security
Production and fulfilment security
Supply Chain
How do I get access to documents here?
Most of what you need is open and needs no request: our security whitepaper, the control lists, sub-processor categories with countries and transfer mechanisms, the vulnerability disclosure policy, the status page and our published legal documents. For the restricted material — the names of our production partners, the penetration test summary, completed security questionnaires, the insurance certificate and our internal policies — submit a request through the form on this page, accepting the confidentiality terms shown there. We respond within one business day. We review each request rather than granting access automatically, because a gate that opens for anything typed into it is not a control. The review is a sanity check, not a negotiation: we confirm the organisation exists and is not a competitor. Approval is the normal outcome, and requests are never routed to sales.
Do I need to sign an NDA?
Not usually. The request form carries confidentiality terms you accept when you submit it — you agree to use the materials only to evaluate DBC1 or administer an existing relationship, to share them only with colleagues and advisers who need them, and not to publish them. Those obligations last three years, and indefinitely for anything that is a trade secret. If your organisation requires a signed agreement instead, e-mail security@dbc1.com and we will send our mutual NDA. That adds a day or two but changes nothing about what you receive. Documents released this way are watermarked with your name, organisation and the date.
How do I hear about changes?
Two different things, and they work differently. Documents and controls on this page — use the subscribe option here and you will be told when something is published or updated. Sub-processor changes are not handled through this page. If you are a customer, we notify your data protection contact directly and in writing at least 30 days before we add or replace any sub-processor, together with a revised annex, and you have a right to object. That notice goes to you individually rather than being published, because a change that gives you a right to object should not depend on you noticing a website update.