---
title: "Security — Daras"
canonical_url: "https://daras.com.tr/en/security"
last_updated: "2026-10-07T09:15:00.554Z"
locale: en
meta:
  description: "KVKK-compliant data processing, append-only audit logging, TLS 1.3 and data hosted in the EU (Germany); independent ISO/SOC2 audits on the roadmap. A transparent security posture."
  "og:description": "KVKK-compliant data processing, append-only audit logging, TLS 1.3 and data hosted in the EU (Germany); independent ISO/SOC2 audits on the roadmap. A transparent security posture."
  "og:title": "Security — Daras"
  "twitter:description": "KVKK-compliant data processing, append-only audit logging, TLS 1.3 and data hosted in the EU (Germany); independent ISO/SOC2 audits on the roadmap. A transparent security posture."
  "twitter:title": "Security — Daras"
---

Security · Compliance · Transparency

# **Your data, **secure** by default.**

AES-256-GCM encrypted secrets, append-only audit trail, security gates on every push and round-the-clock monitoring. Security is the foundation of Daras, not an add-on; independent audit, penetration testing and field-level encryption of customer data are on our roadmap.

CI quality and security gates

**80+**

Zero-downtime deploys

**24/7**

Audit log

**Append-only**

Active monitoring

**24/7**

Certifications

## Certification path,

Documents will be shared on this page as certification processes complete. We provide security documentation on request under a confidentiality agreement.

Information security management

**ISO 27001**

Our information security management system is built to ISO 27001 requirements; independent certification is on our roadmap.

On the roadmap

Independent audit report

**SOC 2 Type II**

Processes and controls are designed around SOC 2 principles; an independent Type II audit is planned.

Planned

Card data handling standard

**Payment security standard**

Card data never touches Daras infrastructure; payments are tokenized and processed through payment-security certified payment institutions.

Via payment institutions

Personal data protection

**KVKK**

KVKK compliance is actively maintained: data processing inventory, disclosure notices and a data-subject request channel are in place.

KVKK

Three pillars

## Infrastructure,

The Daras security model rests on three pillars — each pillar is validated by an independent audit and evidence.

Infrastructure

- Data centresGermany (EU)
- Cloud providerServers located in Türkiye
- Secret encryptionAES-256-GCM
- In transitTLS 1.3 only
- Backup3× / 4 hours
- Disaster recoveryRedundant

Access

- SSOSAML 2.0 / OIDC
- Two-factorTOTP (team) · passkey (customers)
- RBACGranular + IP fence
- AuditFull · immutable
- Data export48 hours
- Role-based accessActive

Contract

- Status transparencyLive page
- Service termsBy contract
- Data ownershipCustomer
- DPAStandard included
- Response timeTarget by severity
- MSATurkish / English

FAQ

## Questions your

The 8 questions we receive most often in RFPs. For deeper technical questions, write to security@platform.contactEmailDomain.

All production data is hosted in a data centre in Germany (EU) and processed under KVKK; a move to Türkiye is planned.

Get started

## **Try it in your trial store, go live when you are ready.**

The migration team moves your products, customers, orders and theme; a 301 redirect map keeps your SEO intact.

[**Start free**](https://app.daras.com.tr/register) [**Developer portal**](https://developers.daras.com.tr/docs)