/ trust / v1.0 / april 2026 / stavanger / norway

Your data, handled with the same craft we apply to everything.

Solidlab builds and operates software for clients and portfolio companies. This page shows how we keep data safe — the stack, the subprocessors, the legal agreements. Nothing hidden.

Four non-negotiables.

The rules we apply to every system we build and every engagement we take on.

/ 01

Privacy by design

We collect what the service needs. Nothing more. Features that work without personal data, do.

/ 02

Encryption everywhere

TLS 1.3 in transit. AES-256 at rest. Every database, every backup, every API — encrypted by default.

/ 03

EU data residency

Production data lives in Ireland and Stockholm. Transfers outside EEA only with SCC or adequacy decision.

/ 04

Transparent subprocessors

Every third party we use is listed publicly — what they do, where, and why.

Built on certified infrastructure.

We don't run our own data centers. We build on vendors with enterprise-grade certifications — so every product inherits that foundation.

Vercel

Application hosting & edge network.

SOC 2 Type IIISO 27001

Supabase

Database & auth, EU region.

SOC 2 Type IIEU-west-1

Stripe

Payments & subscription billing.

PCI DSS L1

Cloudflare

DNS, DDoS protection, edge.

ISO 27001

AWS Ireland

Underlying cloud for Supabase EU.

ISO 27001

Resend

Transactional email, EU region.

GDPR compliant

Legal documentation.

All agreements under Norwegian law, aligned with GDPR. PDFs available on request.

The legal entity.

Solidlab is operated by Stå på Pinne AS — a Norwegian limited company, based in Stavanger.

/ legal entity Stå på Pinne AS
/ org number 935 233 488
/ address Tunveien 13, 4016 Stavanger, Norway
/ trading name Solidlab
/ privacy contact privacy@solidlab.ai
/ security contact security@solidlab.ai
/ jurisdiction Norwegian law / Stavanger tingrett

Need a signed DPA?

Security and privacy questions answered within 48 hours.

Get in touch →