Keepit trust center

Keepit holds ISO 27001 certification and an independent SOC 2 Type II audit report, delivering regulatory-ready SaaS backup and recovery to organizations worldwide

Globally recognized certifications

ISO 27001 certification demonstrates Keepit’s commitment to robust information security practices. Our certified ISMS safeguards your data with strict access control, risk management, and data integrity standards.

Request documentation

SOC 2 Type II audit reports verify Keepit’s operational controls, assuring clients of consistent data protection. Our independent audits ensure compliance and security for critical SaaS data.

Request documentation

TISAX is a European information security standard developed by the German Association of the Automotive Industry (VDA). It evaluates how effectively organizations protect sensitive information, including customer data and intellectual property.

Request documentation

TX-RAMP is Texas's state-level cloud security framework that standardizes risk assessment, authorization, and continuous monitoring for cloud services used by state agencies. 

Request documentation

EcoVadis certification is a globally recognized sustainability rating that evaluates a company’s environmental, social, and governance (ESG) performance across its supply chain. 

Request documentation

Data center certifications

EMEA

Copenhagen, Denmark

(Cibicom)

ISO/IEC ISO 27001, DS/EN ISO 9001, ISAE 3402

EMEA

Frankfurt, Germany

(Equinix)

ISO 27001, ISO 9001, ISO 22301, ISO 14001, ISO 45001, ISO 50001, PCI DSS, SOC I type II, SOC II type II, Cyber Essentials, EU Code of Conduct, Climate Neutral Data Centre Pact 

EMEA

London, United Kingdom

(Equinix)

ISO 27001, ISO 9001, ISO 22301, ISO 14001, ISO 45001, ISO 50001, PCI DSS, SOC I type II, SOC II type II, Cyber Essentials, EU Code of Conduct, Climate Neutral Data Centre Pact

EMEA

Zurich, Switzerland

(Equinix)

ISO 27001, ISO 9001, ISO 22301, ISO 14001, ISO 45001, ISO 50001, PCI DSS, SOC I type II, SOC II type II, Cyber Essentials, EU Code of Conduct, Climate Neutral Data Centre Pact

Americas

Washington DC, USA

(Equinix)

ISO 27001, ISO 22301, PCI DSS, NIST 800-53, SOC I type II, SOC II type II, HIPAA, HECVAT

Americas

Toronto, Canada

(Equinix)

ISO 27001, ISO 22301, PCI DSS, SOC I type II, SOC II type II

APAC

Sydney, Australia

(Equinix)

ISO 27001, ISO 14001, ISO 50001, ISO 9001, ISO 22301, SOC I type II, SOC II type II, PCI DSS

Compliance across global standards

Keepit supports your compliance efforts by providing independently stored, immutable backups with documented security controls - helping you meet specific requirements under GDPR, NIS2, DORA, and HIPAA   

Frequently asked questions

How can Keepit backup help you meet GDPR compliance? 

Keepit helps ensure GDPR compliance by providing strong data protection against ransomware and supporting the implementation of essential regulatory workflows. Keepit fully implements GDPR's Article 17 and Article 32, making Keepit an essential tool for your GDPR compliance efforts. 

To learn more read the Keepit for GDPR compliance whitepaper

How does Keepit backup help you meet HIPAA compliance?

The Health Insurance Portability and Accountability Act (HIPAA) mandates that related documents must be retained for a minimum of six years from their creation, or, in the case of policies, from their last effective date. These retention requirements often surpass the default capabilities provided by SaaS applications. Keepit, however, offers up to 99 years of customizable retention options.  

To learn more read Keepit for HIPAA compliance.  

Can Keepit enable NIS2 compliance? 

Keepit facilitates compliance with the EU directive on protecting digital infrastructure, sensitive business information, and personal data. Ensuring cyber resiliency requires storing backups separately from primary data in an independent cloud infrastructure. This approach ensures compliance and business continuity, providing 24/7 data accessibility and robust recovery capabilities, which are key features of Keepit's backup and recovery service. 

Learn more about Keepit for NIS2 compliance

What are Keepit’s certifications? 

Keepit holds ISO 27001 certification and an independent SOC 2 Type II audit report. Additionally, Keepit has successfully obtained industry-recognized certifications such as TISAX, TX-RAMP and EcoVadis, with more certifications planned.

What are Keepit’s data center certifications? 

All of Keepit's data centers conform to a high physical security baseline and hold ISO 27001 certification, supplemented by additional security standards. e.g. SOC-2, PCI/DSS, HIPAA, and NIST. 

Where will my data be stored with Keepit?  

Your backup data will be stored exclusively within the Keepit data center location of your choosing.

To support data sovereignty requirements, customer data is stored within Keepit’s selected regional data locations in the Americas, Europe, or Asia-Pacific. Each region operates independently and is geographically isolated from the others, while leveraging an active-active architecture across multiple data centres within the region. This provides high availability, resilience, and redundancy, while ensuring that customer data remains within the chosen geographic region.

See a full list of Keepit’s data centers and locations.