We employ strict security measures at the organizational, application, and infrastructure levels to ensure security of customer data and our systems. These include:
If you need more information about our security policy, guarantees, and infrastructure, please contact us for detailed documentation.

We make real-time and historical platform status completely transparent and notify all our customers about any incident and outage activities on our Status Page. We offer 99.9% uptime commitment to our Enterprise customers.
PPM Express utilizes many possibilities of our database and cloud infrastructure providers to store the data secure and prevent any data loss in case of possible disaster scenarios. These include daily continuous backups, regional backups, geo-replication of data across three Azure availability zones, encryption of backup data, recovery procedures and plan for restoring services.

We continuously evaluate requirements from various legislations (global, EU originated) and build a strong privacy and security program to provide our customers with the assurance they need for the privacy and protection of their data.
Review our Privacy Policy to learn more about how we manage and protect our customers’ information. Please see our Security and Privacy whitepaper for more details about our privacy program.

PPM Express has evaluated GDPR requirements and our current security and data privacy practices to ensure compliance with new regulations. To prepare for GDPR, we have undertaken some research and changes, both small and large ones.These include:
PPM Express helps to make compliance with GDPR easier.
Hosting, certifications, encryption, availability and data protection.
No. PPM Express does not hold its own SOC 2 or ISO 27001 certificate, and we would rather tell you that plainly than point at somebody else's. The platform runs on Microsoft Azure, whose data centres hold SOC 1, SOC 2 and ISO accreditation, and we operate to the practices those frameworks describe: encryption in transit and at rest, tenant segregation, enforced two-factor authentication for server access, staff access only over a corporate VPN, monthly vulnerability management, and documented backup and recovery procedures. What we cannot hand you today is an audited certificate in our own name. If your procurement process requires one, tell us early and we will work through your security questionnaire directly rather than waste your time.
On Microsoft Azure. Data is encrypted in transit and at rest using FIPS 140-2 compliant algorithms, tenants are segregated, and backup data is encrypted as well. Data is geo-replicated across three Azure availability zones.
A 99.9% uptime commitment for Enterprise customers. Real-time and historical platform status is published on our status page, and we notify customers about incidents and outages there.
Daily continuous backups, regional backups, geo-replication across three Azure availability zones, encrypted backup data, and documented recovery procedures for restoring services.
Yes. We provide a DPA to any customer on request. Email legal@ppm.express and we will send it. We also provide data transfer mechanisms for personal data moving outside the European Economic Area.
Yes, single sign-on is supported. Two-factor authentication is enforced for server access, staff work only over a corporate VPN, and vulnerability management runs monthly.