SECURITY

Enterprise-grade security & compliance,
built in from day one

schedule.so meets rigorous standards for the security and confidentiality of user data. Our compliance features satisfy some of the most stringent security standards in the industry — so you can schedule with confidence.

Data security at its best

Data Encryption (at rest & in transit)

Your data is encrypted from start to finish — while it's stored and while it's moving.

Storage per FIPS 140-2 standards

We store sensitive data in line with FIPS 140-2 standards — the same grade used by government systems.

Automated regular backups

Your data is backed up regularly so nothing ever gets lost.

Always-on encryption & captcha

Every booking page ships with always-on encryption, inbuilt spam protection, and always-on captcha.

Built for privacy & control

Whether you're handling health info, financial data, or customer details, we help you keep it safe without extra effort.

Compliance-first, backed by data residency

While others promise compliance "soon," schedule.so ships with it today.

Enterprise-grade compliance

With schedule.so you're not just data-residency compliant — you're compliant with the most stringent compliance frameworks in the industry.

SOC 2

SOC 2

HIPAA

HIPAA

ISO 27001

ISO 27001

GDPR

GDPR

SOC 2

SOC 2

HIPAA

HIPAA

ISO 27001

ISO 27001

GDPR

GDPR

SOC 2

SOC 2

HIPAA

HIPAA

ISO 27001

ISO 27001

GDPR

GDPR

SOC 2

SOC 2

HIPAA

HIPAA

ISO 27001

ISO 27001

GDPR

GDPR

PIPEDA

PIPEDA

PHIPA

PHIPA

Singapore PDPA

Singapore PDPA

NZ Privacy Act

NZ Privacy Act

PIPEDA

PIPEDA

PHIPA

PHIPA

Singapore PDPA

Singapore PDPA

NZ Privacy Act

NZ Privacy Act

PIPEDA

PIPEDA

PHIPA

PHIPA

Singapore PDPA

Singapore PDPA

NZ Privacy Act

NZ Privacy Act

PIPEDA

PIPEDA

PHIPA

PHIPA

Singapore PDPA

Singapore PDPA

NZ Privacy Act

NZ Privacy Act

Data Residency Available In

Decide where your data lives. schedule.so offers data residency in the United States (HIPAA) and the European Union (GDPR).

🇺🇸
🇪🇺

Enterprise-grade compliance — for all our users

SOC 2 Type 2

Protect data with audited systems for access, security, and control.

CCPA

Align with California privacy rules for user data and storage policies.

HIPAA Compliant

schedule.so handles sensitive health data securely and meets US healthcare requirements.

GDPR EU Compliant

Follow EU data privacy rules with full control over where and how your data is stored.

PIPEDA Compliant

Store and process Canadian user data in line with national privacy laws.

Australia DPA

Meet Australia's Privacy Act requirements with region-based data storage.

ISO 27001:2013

Follow international cloud security best practices for safer data management.

GDPR UK Compliant

Follow UK data privacy rules with full control over where and how your data is stored.

How schedule.so ensures security

Vulnerability tracking & resolution

We monitor for threats round the clock. From patching issues to fixing misconfigurations, our systems catch and handle problems before they turn into risks — you stay protected without lifting a finger.

Regular compliance audits

We get audited by independent security experts on a fixed schedule. These checks cover our platform, infrastructure, and data practices — making sure we meet global compliance standards, not just internal ones.

Strong operational policies

Security isn't just about tools — it's about how your team works. From access permissions to change tracking, we've locked down every part of the workflow so nothing slips through the cracks.

How schedule.so security empowers you

2 Factor Authentication

Secure your account with a second step. schedule.so supports time-based codes from apps like Google Authenticator, adding a strong layer of protection beyond your password.

Data Processing Addendum

Our DPA outlines how we handle personal data on your behalf, with terms for security, privacy, and compliance — aligned with global laws like GDPR and HIPAA.

Password-protected booking pages

Limit access to the people who need it. Set a password before entry — perfect for internal scheduling, gated bookings, or early-stage campaigns.

Security FAQs

Yes. schedule.so is SOC 2 Type 2 compliant, with audited systems for access, security, and control, verified by independent auditors on a fixed schedule.

You choose. schedule.so offers data residency in the United States (HIPAA) and the European Union (GDPR). Your data stays in the region you select.

Always. Data is encrypted both at rest and in transit, and sensitive data is stored in line with FIPS 140-2 standards.

Yes. Our DPA outlines how we handle personal data on your behalf, with terms for security, privacy, and compliance aligned with GDPR and HIPAA.

Yes. schedule.so handles sensitive health data securely and meets US healthcare requirements, including support for US data residency.

schedule.so aligns with SOC 2 Type 2, HIPAA, ISO 27001:2013, GDPR (EU & UK), CCPA, PIPEDA, and the Australia DPA, among others.

Secure scheduling, ready from day one

Get enterprise-grade security and global compliance built in by default — no upgrades, no paywalls, no compromises.

✓ SOC 2 Type 2 & ISO 27001
✓ HIPAA & GDPR compliant
✓ US & EU data residency
Dashboard