Security you don't have to configure.
Talk with Guest is engineered so the default configuration is safe. Data lives in Portugal by default, moves inside the EU only on customer request, and never leaves the EU. Every request is authenticated, every access is audited, every backup is tested.
What the platform is built on
- All customer data hosted inside the European Union — mainland Portugal (primary), Ireland (secondary), no US region
- Encryption in transit (TLS 1.3) and at rest (AES-256) for every data store, including database, object storage, backups and logs
- ISO 27001 aligned controls and SOC 2 Type II readiness in progress with independent auditors
- Continuous vulnerability scanning of every deployment, third-party dependencies monitored daily
- Access to production systems is passwordless (WebAuthn), MFA required for all staff, audit-logged with retention of 24 months
Compliance is the baseline, not an add-on
Talk with Guest, Lda is registered with the Comissão Nacional de Proteção de Dados (CNPD) and complies with Regulation (EU) 2016/679 (GDPR) and Portuguese Law 58/2019.
Data processing addendum
Our GDPR-compliant DPA is available as an annex to every subscription, executed automatically on onboarding. See the DPA text.
Subprocessor register
Every third party that processes data on our behalf is listed with the country, purpose and safeguards. Updated with 30 days' notice for changes.
Data subject rights
Access, rectification, erasure, portability, restriction of processing and objection are supported natively — the guest CRM includes a right-to-be-forgotten workflow.
Breach notification
Should the worst happen, we notify the CNPD within 72 hours per GDPR Article 33, and affected customers within 24 hours of confirmation.
DPO
Rita Ferreira Marques is our named DPO. Reach her at dpo@talk.mindbery.org for any privacy question.
PCI DSS
Card data is never stored on Talkguest. We tokenise through Stripe, SumUp, Mollie or Adyen — the PSP takes the PCI scope.
How we run it day to day
- Deploys are audited. Every production deployment is reviewed by at least two engineers, tied to a signed commit, and rolled forward through canary before it reaches all customers.
- Backups are tested. Every backup is decrypted and mounted into a scratch environment weekly to verify the restore path — a backup that has not been restored is a backup that does not exist.
- Incidents have owners. Every incident above severity 3 has a named incident commander from minute one, and a postmortem in customer-visible language within seven days.
- Vendors are reviewed annually. Every subprocessor is re-evaluated once a year — data residency, breach history, security posture.
- Reporting security bugs is safe. Our vulnerability disclosure programme guarantees no legal action against good-faith researchers. Report at abuse@talk.mindbery.org.