SOC 2 Type II
Independent validation of our controls for security, availability, processing integrity, confidentiality, and privacy.
Download report →Metadata maintains the highest standards of information security, compliance, and privacy. Our proactive approach keeps customer data secure and aligned with international regulations — so your team can move fast with certainty.
Independent, audited validation of how we secure and govern your data.
Independent validation of our controls for security, availability, processing integrity, confidentiality, and privacy.
Download report →Systematic, ongoing management of information security risks across people, processes, and IT systems.
Download certificate →GDPR compliance and privacy-by-design implementation across the platform, with systematic privacy management.
Download certificate →Defines how we handle your data as a processor — ensuring GDPR compliance and clear data-protection responsibilities.
View DPA →Security and privacy are built into how Metadata operates — from our ISMS to everyday team practices.
Our Information Security Management System is built on ISO 27001, with SOC 2 Type II audits and ISO 27701 privacy controls layered on top, reviewed regularly to adapt to evolving threats.
A risk-management framework identifies, evaluates, and mitigates risks, backed by advanced encryption in transit and at rest, strict access controls, and authentication.
We run regular internal and external audits to review compliance with our security policies and align with evolving global standards.
Every team member is trained on the latest threats and best practices — data privacy, cyber hygiene, and maintaining a strong security posture.
Our privacy policies safeguard personal and business information, adhere to international privacy laws, and provide transparency on data usage, rights, and protections.
Metadata holds three comprehensive certifications: SOC 2 Type II (operational security), ISO 27001 (information security management), and ISO 27701 (privacy management). Together they affirm our commitment to the highest standards for security, confidentiality, integrity, availability, and privacy. Download our certifications and reports →
ISO 27001 shows we have strong cybersecurity policies and procedures to protect against breaches and threats. ISO 27701 shows we respect privacy rights and comply with GDPR and international privacy regulations. SOC 2 Type II proves these security and privacy controls actually work effectively in our daily operations.
Yes. Our ISO 27701 certification specifically validates our GDPR compliance and privacy-by-design implementation, demonstrating systematic privacy controls and respect for data-subject rights across our platform.
We use advanced encryption to protect data at rest and in transit, plus stringent access controls and multi-factor authentication so that only authorized personnel can access sensitive information.
We conduct regular internal and external audits to assess and improve our security posture, identify potential vulnerabilities, and ensure ongoing compliance with our security policies and standards.
Our plan involves immediate action to contain and assess any security breach, followed by remediation steps and communication with affected parties, prioritizing swift action to minimize impact and restore normal operations.
We activate our incident response plan, notify affected users and regulatory bodies as required by law, investigate the breach, prevent future occurrences, and support affected users in mitigating potential damage.
Yes. Customers can request access to our security policies and certain compliance reports, which provide detailed insight into how we manage and protect data.
Yes. Our comprehensive DPA outlines our data-processing terms and how we comply with applicable data-protection laws. It is accessible on our website and is an integral part of our customer contracts.
Users can contact our support team for more information or to raise concerns. We are committed to addressing all inquiries and providing the support needed to ensure confidence in our data-protection practices.
Book a walkthrough with security and marketing in the room, and request our SOC 2, ISO, and DPA documentation.