generated: '2026-09-18' method: searched probe: true source: https://statable.com/security url: https://statable.com/security # Statable (Key Arg B.V.) holds NO third-party audit certifications of its own. # Its published compliance posture is GDPR (EU/Netherlands jurisdiction) plus a DPA # and sub-processor disclosure. The SOC 2 / ISO 27001 / PCI DSS names on the security # page belong to its SUB-PROCESSORS (NorthC, Bunny, Stripe, Google), not to Statable # — recorded separately below so they are not miscredited to the provider. certifications: [] compliance: - id: GDPR scope: EU/Netherlands jurisdiction; cookieless, no consent banner in most jurisdictions evidence: https://statable.com/gdpr - id: DPA scope: Data Processing Agreement offered evidence: https://statable.com/dpa sub_processor_certifications: - vendor: NorthC Datacenters holds: [ISO/IEC 27001, SOC 2 Type II] - vendor: Bunny (CDN) holds: [SOC 2 Type II, ISO/IEC 27001:2022] - vendor: Stripe (billing) holds: [PCI DSS Level 1] - vendor: Google holds: [SOC 2, ISO 27001] evidence: - source: https://statable.com/security note: security policy + sub-processor disclosure page (JS-rendered) - source: https://statable.com/services note: sub-processor list