---
title: "55 Degrees Security Practices"
canonical: "https://support.55degrees.se/space/SECURE/1669562852/55%20Degrees%20Security%20Practices"
format: markdown
---
**Last Updated: **8/26/2026  
*This page is intended to be an evergreen summary of 55 Degrees' security practices and points to the authoritative sources for current, product-specific, contractual, and monitored information.*

55 Degrees knows security is critical and continually improves its practices. For the most current view of our technical and organizational measures, monitored controls, compliance status, certificates, audit reports, and policy evidence, please visit our Trust Center.

[https://trust.55degrees.se](https://trust.55degrees.se)

For legal, privacy, and product-specific terms, this page should be read together with the applicable documents listed below.

- [55 Degrees Privacy Statement and Policies](https://www.55degrees.se/legal/privacy)
- [Customer Agreements for Cloud Products](https://www.55degrees.se/legal/customer-agreements)
- [Customer Agreements for On-Prem Products](https://www.55degrees.se/legal/customer-agreements/onpremise-products)
- [Supplier and sub-processor information](https://support.55degrees.se/space/SECURE/2014216193)
- [Product-specific Data Security & Privacy Statements in the Support Portal](https://support.55degrees.se/)

Please contact us via our Support Portal at [https://support.55degrees.se](https://support.55degrees.se) if you have any questions.

---

## Security and compliance program

55 Degrees maintains an Information Security Management System (ISMS) designed to support our ISO 27001 certification and SOC 2 Type II compliance. Our program includes governance, risk management, security policies, access controls, vendor management, secure development practices, monitoring, incident response, and regular review of controls.

[Visit our compliance page](https://www.55degrees.se/trust) to learn more about our certifications and how to access certificates and audit reports.

## General technical and organizational measures

The measures below summarize the main categories of technical and organizational measures that 55 Degrees maintains as part of our security and data protection program. They are illustrative and not exhaustive; the detailed and current description of our implemented measures is maintained in our Trust Center.

- Documented information security and data protection policies, reviewed on a regular basis.
- Clearly defined internal roles and responsibilities for information security and personal data protection.
- Confidentiality obligations applicable to personnel authorized to process personal data.
- Role-based access controls and least-privilege access principles.
- Strong authentication mechanisms, including multi-factor authentication for privileged access.
- Encryption of personal data in transit and at rest using industry-standard cryptographic methods.
- The ongoing confidentiality, integrity, availability, and resilience of processing systems and services.
- Regular testing, assessment, and evaluation of the effectiveness of technical and organizational measures.
- Secure system development practices and controlled change management processes.
- Procedures for the detection, handling, and management of personal data breaches, including notification procedures.
- Data backup, recovery, and business continuity arrangements to ensure availability and timely restoration of access to personal data.
- Sub-processor management processes and contractual data protection commitments.

Many Trust Center materials, including current control status, passing TOMs controls, certificates, policy evidence, and other standard assurance information, are available directly from the Trust Center. More restricted assurance documentation, including 55 Degrees' SOC 2 Type II report, may be requested through the Trust Center and is made available under a mutually agreed non-disclosure agreement.

## Product-specific information

Because each 55 Degrees product works differently, product-specific details about data access, storage, processing, subprocessors, and security considerations are maintained outside this page. Please refer to the relevant product Data Security & Privacy Statement in our Support Portal and the applicable customer agreement or DPA.

In general, 55 Degrees strives to access, process, and store as little customer data as possible. Where a product is installed into a customer-controlled platform, such as Atlassian or Azure DevOps, the product architecture and data handling depend on the capabilities and limitations of that platform and on the specific product functionality.

## On-premise products

For on-premise products, the product is hosted on the customer's infrastructure. Product-specific data handling and any ancillary processing, such as support interactions, are described in the applicable on-premise customer agreement, DPA, and product-specific privacy documentation.

## How to use this page

This page is a stable summary and navigation point. If there is a conflict between this page and our Trust Center, product-specific privacy statements, customer agreements, DPAs, or other legal documents, the more specific or more current document should be treated as the authoritative source.

> 📝 For the most up-to-date view of our technical measures and monitored controls, visit [https://trust.55degrees.se](https://trust.55degrees.se).

> ℹ️ *Please note that this document is not a legal document or a guarantee. It should be treated as guidance on what 55 Degrees strives to accomplish in this area.*