BookOS

Security & trust

Last updated: 3 June 2026

We treat the security of customer and end-customer data as a first-class product requirement. This page summarises the controls we operate today, the vendors we rely on, and where to find authoritative information. For the contractual version, see Schedule 2 of our DPA.

Data protection

Access & authentication

Reliability & recovery

Vulnerability management

Monitoring & incident response

Data residency & sub-processors

Application and database are hosted in the EU. A small set of sub-processors is engaged to deliver the Service. The current list, with role, location, and transfer mechanism, is published at bookos.io/legal/subprocessors and forms part of our DPA.

Compliance & certifications

Security questionnaires & due diligence

Enterprise customers may request our standard security questionnaire response (CAIQ-Lite based) and the latest summaries of third-party assessments by emailing security@bookos.io. We respond within 10 business days.

Reporting security issues

Report a suspected vulnerability to security@bookos.io per the rules in our disclosure programme. We do not pursue good-faith researchers who follow the published policy.

Security & trust — BookOS