Get access

Security · Whitepaper · 2026 edition

Guest Talk security whitepaper.

This whitepaper details the technical and organisational measures Guest Talk implements to protect customer and guest data. It is written for the security teams of prospective enterprise customers and for auditors reviewing our posture against SOC 2, ISO 27001 and the Estonian equivalent regulatory frameworks. Where a specific control is more detailed than fits this document, we reference the internal standard by name and provide it under mutual NDA on request.

1. Company and governance

Guest Talk OU is a private limited company registered in Estonia (registration 14892715) at Sepapaja tn 6, 15551 Tallinn, Estonia. The information security function is led by the Chief Information Security Officer, who reports to the CEO and has a dotted line to the Data Protection Officer. Security matters are reviewed monthly at the executive team meeting and quarterly at the board.

Governance documents include the Information Security Policy, the Acceptable Use Policy for staff, the Vendor Risk Management Standard, the Data Classification Standard, the Access Control Standard, the Cryptography Standard, the Incident Response Plan, the Business Continuity Plan and the Disaster Recovery Plan. All documents are reviewed annually or upon material change.

2. Compliance posture

  • ISO/IEC 27001 — controls aligned; formal certification underway with an accredited certification body, expected completion Q4 2026.
  • SOC 2 Type II — controls aligned to the Trust Services Criteria for Security, Availability and Confidentiality; independent audit performed annually.
  • GDPR — primary regulatory framework; comprehensive Privacy Policy and DPA published.
  • PCI DSS — scope limited by outsourcing card handling to Stripe (a PCI DSS Level 1 Service Provider); Guest Talk annually completes SAQ-A.
  • NIS2 — monitored; we do not currently meet the size threshold, but the technical controls align with essential entity requirements.

3. Cloud architecture

Guest Talk runs on Amazon Web Services in the eu-central-1 region (Frankfurt). The production environment consists of stateless application services (ECS on Fargate) in front of managed data stores (RDS PostgreSQL, ElastiCache Redis, S3 for object storage, DynamoDB for high-throughput ephemeral state). All services run in a dedicated Virtual Private Cloud with segmented subnets for application, data, and management planes. Public traffic ingress is only via a Cloudflare Enterprise edge and an AWS ALB with Web Application Firewall rules.

4. Encryption

All data at rest is encrypted with AES-256 using AWS KMS-managed keys. Customer master keys are unique per environment; automatic key rotation is enabled with a 12-month cadence. All data in transit is encrypted with TLS 1.3 on public endpoints and TLS 1.2+ on internal service-to-service traffic. Mutual TLS is enforced between core services in production. Backups are encrypted at rest and, when moved off-region for disaster recovery, are additionally encrypted with a separate KMS CMK.

5. Identity and access management

Guest Talk personnel authenticate via a centralised identity provider (Okta) with hardware-backed MFA required for production access. Role-based access control follows the least-privilege principle; production access is scoped to the specific service and environment required for the task. Access reviews are conducted quarterly and after any material role change; access to raw customer databases is limited to a small SRE team and requires a break-glass procedure with dual approval.

6. Application security

The software development lifecycle requires code review by at least one engineer other than the author, plus successful static analysis (Semgrep, custom rules), dependency scanning (Dependabot with our own severity policy), and unit and integration test suites. Container images are scanned for known vulnerabilities before deployment; critical CVEs block deploy without an accepted-risk exception logged in the security backlog. Secrets are never checked into source; secret rotation is automated where the underlying service supports it.

7. Vulnerability management and penetration testing

Automated vulnerability scanning runs continuously against the infrastructure and application. Manual penetration testing is conducted annually by an independent CREST-accredited firm; the executive summary is available under NDA. Additional targeted testing is performed for major architectural changes and for any customer-requested scope. Findings are triaged and remediated per severity: critical within 48 hours, high within 30 days, medium within 90 days.

8. Incident response

The Incident Response Plan is aligned with NIST SP 800-61 and covers detection, triage, containment, eradication, recovery and post-incident review. The on-call rotation is 24x7 with 15-minute page-response SLA for critical incidents. Tabletop exercises are conducted quarterly, and the plan is fully rehearsed annually with a mock incident spanning the full response chain.

Customer notification for personal data breaches under the DPA follows the 24-hour SLA to Customer, with the supervisory-authority notification (72 hours) handled by Customer as controller with Guest Talk assistance under Article 33 GDPR.

9. Backup and disaster recovery

Primary databases have point-in-time recovery enabled with 35 days of history. Daily encrypted snapshots are retained for 90 days. Object storage uses versioning plus cross-region replication to eu-west-1 (Ireland) as a disaster recovery region. The Recovery Point Objective is 15 minutes; the Recovery Time Objective is 4 hours. Annual full failover tests are performed to eu-west-1 with time-recorded results shared with auditors.

10. Business continuity

Beyond disaster recovery, Guest Talk's Business Continuity Plan addresses staff availability, communication continuity, vendor failure and pandemic scenarios. All personnel work from a hybrid model with the ability to operate fully remotely; office availability is not a critical dependency. Communications route through independent channels (Slack, phone, video conferencing with two providers) so no single provider outage stops incident response.

11. Physical security

Guest Talk does not operate its own data centres. Physical security controls are inherited from AWS eu-central-1 (Frankfurt), which is SOC 1, SOC 2, SOC 3, ISO 27001, PCI DSS Level 1 and C5 attested. Guest Talk personnel have no physical access to production hardware.

12. Data lifecycle

Customer data is retained for the duration of the subscription plus the 30-day retrieval window plus 90 days for backup rotation as documented in the DPA. On termination, data is deleted permanently at the end of that window with a certification of deletion available on written request. Deprovisioned staff accounts are disabled immediately with data removed from user-scoped stores within 30 days.

13. Sub-processors

Sub-processors are listed in the Privacy Policy and DPA. Each sub-processor is vetted at onboarding (SOC 2 Type II, ISO 27001 or equivalent independent attestation required) and re-assessed annually. Changes to the sub-processor list are notified to Customers with at least 30 days' notice.

14. Vendor risk

All vendors with access to production, personal data or authentication systems undergo a security review before onboarding: attestations, questionnaires, and (for critical vendors) a technical deep-dive. The Vendor Risk Register is reviewed quarterly by the CISO and the DPO.

15. People and training

All personnel complete GDPR and security awareness training within two weeks of joining and refresher training annually. Engineering staff complete secure coding training annually. Background checks (where permitted by local law) are performed for staff with access to production data.

16. Reporting a security concern

If you believe you have identified a security vulnerability in Guest Talk, please report it to security@talkg.fabriza.org. We follow the coordinated disclosure principles: acknowledgement within one business day, initial assessment within 5 business days, and public disclosure only after remediation and with the reporter's coordination. Responsible reporters may be recognised in our security acknowledgements page unless they prefer to remain anonymous.

17. Assurance materials

The following materials are available under a mutual non-disclosure agreement:

  • SOC 2 Type II audit report (annual).
  • Penetration test executive summary (annual).
  • Incident Response Plan (annual review cycle).
  • Business Continuity and Disaster Recovery Plans.
  • Vendor Risk Register summary.

18. Contact

Security disclosures: security@talkg.fabriza.org. General security enquiries: dpo@talkg.fabriza.org. Legal correspondence: legal@talkg.fabriza.org.

Enterprise security review?

Request the assurance pack under NDA and we will send it within one business day.

Get access See pricing