Skip to content
Trust Center

Security and compliance are core to PMI.

How the production PMI service describes its cloud, application, product, people and privacy controls.

Compliance framework

Compliance certifications and alignment

SOC 2 Type 2

d2o’s development and production environments are regularly audited. Its SOC 2 Type 2 attestation is performed under SSAE No. 18, the AICPA SOC 2 guide and the 2017 Trust Services Criteria.

ISO 27001:2013

d2o aligns its information-security management practices with ISO/IEC 27001 and its privacy-management extension, ISO/IEC 27701, for controller and processor workflows.

PCI DSS 3.2.1

PMI is operated on Microsoft Azure. Azure maintains PCI DSS Service Provider Level 1 validation, and Azure Policy maps regulatory controls to PCI DSS compliance domains.

NIST SP 800-171 R2

d2o uses Azure Security Benchmark controls and NIST guidance, including NIST SP 800-171 R2, to protect sensitive information and manage risk.

Azure Security Benchmark

PMI uses the Azure Security Benchmark as a cloud-focused control baseline for workloads, data and services across its Azure environments.

Trust Center

Cloud Security

Data center physical security

Production states that PMI uses Microsoft Azure data centers in North-Western Europe (Ireland and the Netherlands), the United States and East Asia, with layered physical access controls. It also states that Azure data centers follow standards including ISO/IEC 27001:2013 and NIST SP 800-53.

Vendor security

d2o conducts security reviews for vendors that can access its systems or Service Data, with the stated aim of ensuring that external partners meet d2o security requirements.

Network security

Production describes a security team in North Europe and West Asia with 24/7 on-call coverage; segmented network zones; Azure and edge-network protections; operating-system, database and network-device scanning; Blue- and Red-team exercises; Azure Secure Score; Azure DDoS Protection Standard; least-privilege production access; mandatory multi-factor authentication; and incident escalation to Operations, Network Engineering and Security teams.

Encryption

Production states that data in transit uses HTTPS/TLS 1.2 or higher and that data at rest uses AES-256 encryption. It also describes service clustering, disaster-recovery planning and cross-region replication.

Availability and continuity

Production states an Azure availability figure of at least 99.06%, depending on resource and configuration, and describes service clustering, network redundancy, availability-zone replication, disaster-recovery plans and regional failover.

Trust Center

Application Security

PMI solutions and websites

The production statement covers PMI R&P, PMI P&L, PMI GoGreen, PMI Task Manager and PMI Plus, together with websites under *.d2o.biz, *.d2o.com and *.d2o.no.

Development security controls

Production describes OWASP Top Ten secure-code training, periodic Red- and Blue-team training, secure open-source frameworks, Quality Assurance review and triage, and logical separation between test and production environments.

Vulnerability management

Production describes Azure Defender for Cloud, vulnerability scanning across servers, databases and network devices, segmented security zones, least-privilege access, multi-factor authentication, Azure Secure Score and 24/7 incident-response coverage.

Trust Center

Product Security

Authentication and credential storage

Production describes native PMI authentication and Microsoft 365 enterprise single sign-on. It states that native authentication supports two-factor authentication by SMS or authenticator app, that passwords require at least eight characters with mixed character classes, and that credentials are stored only as salted one-way hashes.

Access control, audit logs and redaction

PMI is described as using role-based access control with owner, administrator, agent and end-user roles. Production also describes customer-visible redacted audit logs, complete production logs in Azure, and optional manual redaction that anonymizes usernames and activities in logs and database records.

Trust Center

HR Security

Security awareness

Production states that security policies are available to employees and contractors handling PMI information assets, that all employees complete security-awareness training on hire and annually, and that engineers receive annual secure-code training.

Employee vetting

Production states that employees and contractors undergo locally compliant criminal-record, education and employment-history checks and sign non-disclosure and confidentiality agreements.

Development organization controls

Production describes Azure DevOps planning, code review and staging-deployment controls. It states that an Eastern Europe development team reviews production releases and that development and production are separated by Azure region, network controls, RBAC, two-factor authentication and VPN gateways.

Trust Center

Privacy Related Policies

Information collected

Production describes collecting contact and event-registration information, cookie-derived website usage information, customer-authorized source-system integration data and PMI account information. Listed integration sources include POS, F&B and table reservations, time keeping, PMS, RMS, sales and catering, and accounting systems. PMI account removal requests are directed through known customer contacts to support@d2o.com, with anonymization where dependencies prevent deletion.

Website cookies

Production describes session and persistent cookies, including essential, analytics and preference cookies. It also states that third-party social features may collect an IP address, page context and their own cookie under the third party’s privacy policy.

International transfer of information

Production states that client and attendee data is primarily stored in Norway and may be transferred to or accessed from other countries where d2o operates, with the privacy statement continuing to apply.

Third-party links

External sites have independent privacy policies. Production states that d2o is not responsible for their content or activity and invites feedback about concerns.

Trust Center

GDPR Compliance

GDPR commitments

Production states that d2o supports more than 500 customers and 5,000 end users in over ten countries, processes non-sensitive personal data as a SaaS provider, supports customer obligations under GDPR Articles 13–22, and assists with data-subject enquiries where legally permitted and commercially reasonable.

The production list of permitted data is first and last name, email address, job title, employee number and payroll cost, with payroll cost encrypted in transit and at rest.

Read the GDPR orientation in the Knowledge Base.

Personal-data access outside the EEA

Production states that d2o does not move data outside the EU, that encryption prevents processors outside the EEA from identifying natural persons, and that privileges are managed by authorized personnel inside the EEA.

Trust Center

Legal Information

Agreements

d2o publishes a Data Processing Agreement to provide customers and partners with information supporting their own legal and compliance requirements.

Download the Data Processing Agreement (PDF).

Third-party disclosure

Production describes sharing client and attendee data with contracted service providers, affiliates and promotion partners for stated service and operational purposes. It states that d2o does not sell, rent or trade personal information for third-party promotion and may disclose information where required by law, court order or a legal process, or to protect d2o rights.

PMI

The next advantage isn't more revenue. It's converting more of it.

See where your profit is leaking — and what closing the gap is worth for your portfolio.