Attestations
This page is for the person who has been asked to sign off on Headway. It says what has been independently audited, who audited it, what Headway itself does on top, and how to get the underlying reports. It is written to be precise rather than reassuring: where a claim belongs to one of our providers and not to us, it says so.
1. The short version
- Headway does not yet hold its own SOC 2 or ISO 27001 certification. We are a small Australian company and we will not pretend otherwise.
- Headway runs on infrastructure whose operators do hold those attestations, audited by independent third parties, and we inherit their controls under each provider’s shared-responsibility model.
- No cloud provider has reviewed or endorsed Headway’s architecture. DigitalOcean, our primary host, does not offer an “approved architecture” programme of the kind some larger clouds run, so nobody can truthfully claim one on their platform - including us.
- We will answer your security questionnaire directly, and we can provide our host’s SOC 3 report on request and its SOC 2 Type II report under NDA.
2. Where Headway runs
Headway’s application, database and database backups are hosted with DigitalOcean in its Sydney, Australia region. Attachments and uploaded files are stored in Amazon S3 in the Sydney (ap-southeast-2) region. Identity, email delivery and error reporting use providers in the United States, listed in section 4 and in our Privacy Policy.
3. What our primary host attests to
DigitalOcean’s platform is audited against the following. These are DigitalOcean’s attestations, covering the infrastructure and services beneath Headway, not an audit of Headway itself.
| Attestation | Issued by / scope | How to obtain |
|---|---|---|
| SOC 2 Type II | Independent auditor Schellman & Company; 2017 Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality and Privacy | From us, under NDA |
| SOC 3 Type II | Same auditor; the general-use summary of the SOC 2 | From us, on request |
| CSA STAR Level 1 | Cloud Security Alliance self-assessment across the CCM domains | Public register, or from us |
| PCI DSS (SAQ-A) | DigitalOcean holds no cardholder data; Headway does not either - card payments, when enabled, are handled by the payment processor | From us, on request |
| Global PRP | APEC Privacy Recognition for Processors | From us, on request |
| CIS Benchmarks | CIS Foundations and CIS Services benchmarks | From us, on request |
| ISO 27001 (and 9001, 14001, 22301) | Held by the data-centre facilities DigitalOcean operates from, varying by location; DigitalOcean the company is not itself ISO 27001 certified | From us, on request |
DigitalOcean also states it is eligible to process HIPAA and DORA workloads. Headway makes no HIPAA claim: the product is not designed for health information and our Privacy Policy asks you not to put it there.
4. What our other providers attest to
| Provider | Role in Headway | Location | Attestations |
|---|---|---|---|
| Amazon Web Services (S3) | Attachment and file storage | Sydney, Australia | SOC 1, 2 and 3; ISO 27001, 27017, 27018; PCI DSS; IRAP-assessed for the Sydney region. Reports are public on AWS Artifact. |
| Clerk | Authentication and identity | United States | SOC 2 Type II (since May 2022). Not ISO 27001 itself; its infrastructure (Google Cloud, Cloudflare) is. Report available from Clerk on request. |
| Resend | Outbound email delivery | United States | SOC 2 Type II; GDPR Article 28 data-processing addendum in force. |
| Sentry | Error reporting, when enabled | United States | SOC 2 Type II; ISO 27001; HIPAA attestation. Reports available to Sentry customers, which we are. |
This table is kept in step with the sub-processor list in our Privacy Policy. If the two ever disagree, the Privacy Policy is the one we are bound by; tell us and we will fix this page.
5. What Headway itself does
The attestations above cover the ground beneath us. These are the controls we operate ourselves. They are described, not certified; we would rather you knew exactly what they are.
- Encryption in transit. All traffic to the application, and between the application and its providers, is over TLS.
- Tenancy. Every record belongs to a workspace, and every request from a workspace user is scoped to that workspace at the API, not left to the interface.
- Operator access. Headway staff can see the facts needed to run the service - your plan, seats, administrators, sign-in and usage counts - and not your workspace’s records. Where support needs to see those records, it is at your request, with your administrator’s agreement, for a stated reason, and the access is recorded.
- Audit trail. Changes across every module are written to an append-only, actor-attributed audit log that your administrators can read.
- Access to production. Limited to the people who operate the service, by key, not password. Production secrets are not committed to source control.
- Backups. Database backups are taken on a rolling schedule and kept in the same Australian region as the database.
- Deletion. Closing a workspace makes it read-only at once and permanently deletes it 30 days later; deleted items persist in backups only until those backups age out.
- Breach notification. We participate in Australia’s Notifiable Data Breaches scheme and will notify affected administrators, individuals and the OAIC as it requires.
- No third-party analytics inside the application, and no model training on your data.
- Self-hosting. For policies that require it, Headway ships as a single container you can run on your own infrastructure, in which case sections 2 to 4 become your own.
6. What we have not done yet
We have not commissioned an independent penetration test of Headway, and we have not begun a SOC 2 audit of our own. Both are on the plan. When either is complete this page will say so, with dates, and the report or summary letter will be available on the same terms as the provider reports above. Until then, please treat section 5 as our own account of our controls, which is what it is.
7. How to obtain the reports
Email hi@headwaystack.com with the name of your organisation and what you are assessing. We will send DigitalOcean’s SOC 3 and the public AWS and provider material straight back; for DigitalOcean’s full SOC 2 Type II report we will ask you to sign a short mutual NDA first, as its terms require. We will also complete your security questionnaire, and we would rather you sent it to us than guessed at the answers from this page.
8. Contact
Headway Stack (ABN 75 674 802 209) - Melbourne, Victoria, Australia.
Security and compliance: hi@headwaystack.com · Privacy: privacy@headwaystack.com