Enterprise-grade security & compliance,
built in from day one
schedule.so meets rigorous standards for the security and confidentiality of user data. Our compliance features satisfy some of the most stringent security standards in the industry — so you can schedule with confidence.
Data security at its best
Data Encryption (at rest & in transit)
Your data is encrypted from start to finish — while it's stored and while it's moving.
Storage per FIPS 140-2 standards
We store sensitive data in line with FIPS 140-2 standards — the same grade used by government systems.
Automated regular backups
Your data is backed up regularly so nothing ever gets lost.
Always-on encryption & captcha
Every booking page ships with always-on encryption, inbuilt spam protection, and always-on captcha.
Built for privacy & control
Whether you're handling health info, financial data, or customer details, we help you keep it safe without extra effort.
Compliance-first, backed by data residency
While others promise compliance "soon," schedule.so ships with it today.
Enterprise-grade compliance
With schedule.so you're not just data-residency compliant — you're compliant with the most stringent compliance frameworks in the industry.
SOC 2
HIPAA
ISO 27001
GDPR
SOC 2
HIPAA
ISO 27001
GDPR
SOC 2
HIPAA
ISO 27001
GDPR
SOC 2
HIPAA
ISO 27001
GDPR
PIPEDA
PHIPA
Singapore PDPA
NZ Privacy Act
PIPEDA
PHIPA
Singapore PDPA
NZ Privacy Act
PIPEDA
PHIPA
Singapore PDPA
NZ Privacy Act
PIPEDA
PHIPA
Singapore PDPA
NZ Privacy Act
Data Residency Available In
Decide where your data lives. schedule.so offers data residency in the United States (HIPAA) and the European Union (GDPR).
Enterprise-grade compliance — for all our users
SOC 2 Type 2
Protect data with audited systems for access, security, and control.
CCPA
Align with California privacy rules for user data and storage policies.
HIPAA Compliant
schedule.so handles sensitive health data securely and meets US healthcare requirements.
GDPR EU Compliant
Follow EU data privacy rules with full control over where and how your data is stored.
PIPEDA Compliant
Store and process Canadian user data in line with national privacy laws.
Australia DPA
Meet Australia's Privacy Act requirements with region-based data storage.
ISO 27001:2013
Follow international cloud security best practices for safer data management.
GDPR UK Compliant
Follow UK data privacy rules with full control over where and how your data is stored.
How schedule.so ensures security
Vulnerability tracking & resolution
We monitor for threats round the clock. From patching issues to fixing misconfigurations, our systems catch and handle problems before they turn into risks — you stay protected without lifting a finger.
Regular compliance audits
We get audited by independent security experts on a fixed schedule. These checks cover our platform, infrastructure, and data practices — making sure we meet global compliance standards, not just internal ones.
Strong operational policies
Security isn't just about tools — it's about how your team works. From access permissions to change tracking, we've locked down every part of the workflow so nothing slips through the cracks.
How schedule.so security empowers you
2 Factor Authentication
Secure your account with a second step. schedule.so supports time-based codes from apps like Google Authenticator, adding a strong layer of protection beyond your password.
Data Processing Addendum
Our DPA outlines how we handle personal data on your behalf, with terms for security, privacy, and compliance — aligned with global laws like GDPR and HIPAA.
Password-protected booking pages
Limit access to the people who need it. Set a password before entry — perfect for internal scheduling, gated bookings, or early-stage campaigns.
Security FAQs
Yes. schedule.so is SOC 2 Type 2 compliant, with audited systems for access, security, and control, verified by independent auditors on a fixed schedule.
You choose. schedule.so offers data residency in the United States (HIPAA) and the European Union (GDPR). Your data stays in the region you select.
Always. Data is encrypted both at rest and in transit, and sensitive data is stored in line with FIPS 140-2 standards.
Yes. Our DPA outlines how we handle personal data on your behalf, with terms for security, privacy, and compliance aligned with GDPR and HIPAA.
Yes. schedule.so handles sensitive health data securely and meets US healthcare requirements, including support for US data residency.
schedule.so aligns with SOC 2 Type 2, HIPAA, ISO 27001:2013, GDPR (EU & UK), CCPA, PIPEDA, and the Australia DPA, among others.
Secure scheduling, ready from day one
Get enterprise-grade security and global compliance built in by default — no upgrades, no paywalls, no compromises.
