UGC at the scale your procurement team signs off on.
SOC 2 in audit, GDPR, pre-signed DPA, SAML SSO, multi-region and a 99.9% SLA. Built for multi-brand groups, regulated industries and global retail, priced in plain bands your finance team can read.
The procurement pack
1 UK business day- DPA + SCCs, pre-signed
- Sub-processor register
- SIG-Lite questionnaire
- Pen-test executive summary
- SOC 2 audit progress note(Type II in progress)
- MSA redlines accepted
One ZIP, no sales call required. Full detail on the security + DPA page.
What enterprise plans add.
Security + compliance
SOC 2 Type II in audit, with the controls running today. GDPR + UK GDPR. DPA available pre-signed. EU + US data residency.
SSO + RBAC
SAML 2.0 SSO via Okta, Azure AD and Google Workspace. Role-based access with a full audit log.
Rights + provenance
A complete audit trail per piece of content: source, request, approval, expiry. Built for regulated industries.
Multi-region, multi-language
Active-active deployments in EU + US. Hreflang built in. The widget is CDN-cached across 220 PoPs.
Multi-brand + reseller
Workspace-per-brand with consolidated billing. Agency portal for 10+ sub-accounts. Custom domains.
Custom SLAs + support
99.9% uptime SLA. Dedicated CSM. Slack Connect support. Quarterly business reviews.
The security review, without the fortnight of email.
Every document your reviewer will ask for is written, current and ready to send. Here is how the review actually runs.
- 01
You ask
Email or the form below. No discovery call required to get documents.
- 02
The pack lands
One ZIP within one UK business day: DPA, SCCs, sub-processors, SIG-Lite, pen-test summary, audit note.
- 03
Your review runs
Architecture and security questions answered in writing. MSA and DPA redlines negotiated, not refused.
- 04
You sign
Annual or multi-year terms. Procurement portals and PO flows accepted.
Procurement-friendly answers
- Where is data stored?
- AWS eu-west-2 (London) by default; us-east-1 available. EU + UK customers get EU-only routing on request.
- Sub-processors
- AWS, Vercel, Sanity, Cloudflare, Postmark, Twilio, Sentry, Anthropic. Full list in the DPA.
- Pen test cadence
- Annual third-party pen test. Continuous internal SAST + dependency scanning.
- Backup + DR
- Hourly point-in-time. RPO 1h, RTO 4h. Quarterly DR drills with public results.
- Bug bounty
- Yes, disclosed responsibly via security@idukki.io with 90-day disclosure window.
- Custom contracting
- MSA, DPA and SCCs negotiable. Procurement reviews accepted. Annual or multi-year terms available.
Replacing an enterprise tool?
All comparisonsEnterprise
SOC 2 (in audit), SSO, DPA, multi-region. Get the procurement pack.
A dedicated solutions engineer, a security questionnaire pre-filled, and a 30-day pilot scoped to your stack.
- No credit card
- Cancel anytime
- GDPR + SOC 2 (in audit)