Trust Center
Last updated: 23 July 2026
Compliance roadmap
Webithon does not currently hold these certifications. Statuses below reflect our roadmap, not earned badges.
| Certification | Status | Target date | Notes |
|---|---|---|---|
| ISO 27001 | On Roadmap | [placeholder] | Not yet certified |
| SOC 2 Type II | On Roadmap | [placeholder] | Not yet certified |
| GDPR | On Roadmap | [placeholder] | Alignment in progress |
| PCI DSS | On Roadmap | [placeholder] | Not applicable to current products |
Data handling & encryption
All data in transit is encrypted.
Stored data is encrypted at rest.
Access is scoped to what's needed.
Access and system logs are retained.
Data residency options discussed per contract.
Regular backups with tested restore process.
Incident response
Response-time commitment: [placeholder — to be defined in SLA]
Security contact: webithonpvtltd@gmail.com (placeholder — recommend swapping to a dedicated security@ alias)
Subprocessors
| Vendor | Purpose | Region |
|---|---|---|
| Web3Forms | Contact form delivery | US |
| Cloudflare Pages | Website hosting & CDN | US / Global |
| Cloudflare Web Analytics | Privacy-first analytics (no cookies, no PII) | US / Global |
| Google Fonts | Typeface delivery | US |
Request our security overview
We share detailed documentation under NDA.
Procurement FAQ
A data processing agreement template is available on request.
Typically 5-10 business days depending on scope.
Not yet on a fixed cadence — this is on our roadmap.
Client data is deleted within an agreed window per contract terms.
Responsible disclosure
Found a security issue? Email webithonpvtltd@gmail.com with details — we aim to acknowledge reports promptly (formal SLA to follow).
