Trust Center

Updated: February 15, 2026

Welcome to the Keelio Software Trust Center. This page brings together the policies, certifications, and practices that describe how we protect your data and support your compliance needs. Use the links below to review our Privacy Policy and Terms and Conditions, and read on for information about our compliance certifications and incident response practices.

1. PRIVACY POLICY

Our Privacy Policy explains what personal information we collect, how we use it, who we may share it with, and the rights you have over your data, including access, correction, and deletion requests.

Read our Privacy Policy

2. TERMS AND CONDITIONS

Our Terms of Use set out the rules for accessing and using the Keelio Software website and services, including acceptable use, intellectual property rights, and limitations of liability.

Read our Terms of Use

3. COMPLIANCE & CERTIFICATIONS (E.G., ISO, SOC, GDPR)

Keelio Software's infrastructure is hosted with Vultr, whose data centers and control plane maintain a range of independent attestations and certifications, including SOC 2+, ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018, and PCI-DSS, along with alignment to privacy regulations such as GDPR and CCPA.

Compliance artifacts and audit reports (SOC 2 reports, ISO certificates, etc.) are made available directly by Vultr through their customer console. You will need to create your own free Vultr account to view or download these documents:

  1. Visit the Vultr Compliance page and select "Create free account" (or log in if you already have one).
  2. Once signed in at console.vultr.com, open the Account menu and select the Compliance tab.
  3. Download the certifications or attestations relevant to your organization's compliance requirements.

4. INCIDENT RESPONSE PLAN

Keelio Software maintains an incident response plan to detect, contain, and remediate security or data incidents affecting our services, including data breaches and unauthorized access attempts. If we become aware of an incident affecting your data, we will investigate promptly, take steps to limit any impact, and notify affected customers in accordance with applicable law and our contractual obligations.

If you believe you have discovered a security vulnerability or suspect a data or security breach affecting Keelio Software, please report it immediately to support@keelio.com so we can begin our response process.

Read our Incident Response Plan

5. PAYMENT DATA SECURITY

Keelio Software does not store any payment card data on our own systems. All payment processing and storage of payment instrument data is outsourced to Stripe, a PCI DSS Level 1 certified payment provider, so cardholder data is never retained within Keelio Software's infrastructure.

For more information on how Stripe collects, uses, and protects payment data, visit the Stripe Privacy Center.

6. BUSINESS CONTINUITY & DISASTER RECOVERY

Keelio Software maintains a Business Continuity and Disaster Recovery Plan describing how we prepare for and respond to events that could disrupt our services, including infrastructure failures, natural disasters, and other significant outages, with the goal of minimizing downtime and data loss for our customers.

Read our Business Continuity & Disaster Recovery Plan

7. PENETRATION TESTING & VULNERABILITY ASSESSMENTS

Keelio Software periodically reviews the security posture of our public-facing infrastructure, including TLS/SSL configuration and other externally observable security controls, to help identify and remediate potential vulnerabilities.

You can view an independent, up-to-date TLS/SSL configuration report for our website, generated by Qualys SSL Labs:

Qualys SSL Labs Report