DMHub is designed with security at its core — encryption everywhere, granular access controls, audit logs, and a transparent sub-processor list so your procurement team can close fast.
Current certification status across regulatory and industry frameworks.
| Framework | Status | Report |
|---|---|---|
| SOC 2 Type II | In progress | Available on completion |
| GDPR | Certified | — |
| CCPA | Certified | — |
| TCPA | Certified | — |
| HIPAA | N/A | — |
| ISO 27001 | In progress | Available on completion |
| PCI DSS | N/A | — |
| CAN-SPAM | Certified | — |
Enterprise customers can request a copy of our SOC 2 report once issued. Contact security@dmhub.ai
DMHub uses 14 third-party sub-processors to deliver its services. Each processor is under a Data Processing Agreement (DPA) and reviewed annually.
| Processor | DPA |
|---|---|
| Vercel | DPA |
| Neon | DPA |
| Stripe | DPA |
| Twilio | DPA |
| Resend | DPA |
| Cloudflare R2 | DPA |
| Pusher | DPA |
| Inngest | DPA |
| Upstash | DPA |
| Loops | DPA |
| PostHog | DPA |
| Sentry | DPA |
| OpenAI | DPA |
| Anthropic | DPA |
Last updated: May 2026
View full sub-processor list with data types & certifications19 of 20 controls implemented across encryption, access control, monitoring, and more.
Real-time status across all DMHub subsystems.
99.9%
Uptime target (SLA)
Live uptime tracking across database, cache, payments, and real-time subsystems.
View live statusAll incidents, maintenance windows, and postmortems are published publicly on the status page as they happen.
View incident historyDocumentation covering how we handle, protect, and share your data.
Found a vulnerability? We have a responsible disclosure program with safe-harbor protections. We acknowledge reports within 2 business days and keep you updated throughout the remediation process.
Our SOC 2 Type II audit is in progress. Enterprise customers can request the report once issued — it will be shared under NDA.
Request report