Compliance built in from day one
MicroBackups is certified for the world's most stringent data protection standards. Protect your data and your organisation's compliance posture simultaneously.
GDPR
General Data Protection RegulationMicroBackups acts as a Data Processor for personal data of EU residents. We sign a Data Processing Agreement (DPA) upon request. EU customer data is stored within the EEA. We support data subject access requests and deletion rights.
HIPAA
Health Insurance Portability and Accountability ActFor healthcare organisations, MicroBackups signs a Business Associate Agreement (BAA). Our systems and processes are designed to comply with the HIPAA Security Rule, including technical safeguards for electronically protected health information (ePHI).
PCI DSS
Payment Card Industry Data Security StandardMicroBackups is PCI DSS compliant. Our controls address cardholder data environments and the requirements for organisations that process, store, or transmit credit card data.
SOC 2 Type II
Service Organization Control 2Our SOC 2 Type II report, conducted by an independent CPA firm, verifies that MicroBackups' controls for security, availability, and confidentiality have been operating effectively over the audit period. Report available to customers under NDA.
ISO 27001
Information Security Management SystemMicroBackups maintains an ISO 27001-certified Information Security Management System (ISMS). Annual surveillance audits ensure continued compliance with the international standard for information security.
CCPA
California Consumer Privacy ActMicroBackups complies with the CCPA for California residents. Users can request access to their personal data, request deletion, and opt out of data sale (we do not sell personal data).
Privacy Shield
EU–US and Swiss–US Privacy Shield FrameworkMicroBackups participates in and has certified compliance with the Privacy Shield Framework, ensuring trans-Atlantic data transfers comply with EU and Swiss data protection requirements.
Data residency — your data stays where you choose
Select your storage region at setup. Your backup data is stored exclusively in that region — never replicated across borders without explicit configuration.
United States
us-east-1 / us-west-2
European Union
eu-west-1 (Ireland)
United Kingdom
eu-west-2 (London)
Canada
ca-central-1
Australia
ap-southeast-2 (Sydney)
Compliance documentation available on request
Contact our team to request any of the following:
SOC 2 Type II Report
Available under NDA
Data Processing Agreement (DPA)
For GDPR compliance
Business Associate Agreement (BAA)
For HIPAA customers
ISO 27001 Certificate
Available on request
Penetration Test Summary
Annual third-party testing
Sub-processor List
Full list available
Start compliant from day one
14-day free trial. All compliance features included. No credit card required.
Start Free Trial