The rest of the stack, same team.
A public privacy center, a named Data Protection Officer, US business insurance, and the integrations that wire it all into the tools you already run. The pieces that sit alongside compliance and operations — under one contract, on one invoice.
Tell us what you're missing — we'll fill the gaps.
Nothing here is mandatory on day one. A privacy center is the usual first step — it's free to start and it answers most of a security review. The DPO, the cover, and the integrations follow as you grow. Tick what's true.
Tick what's true — we'll scope the rest.
Your answers determine which of the four you actually need. We'll only recommend what earns its place — and flag what's free to start.
Four products. One contract.
Trust
Privacy Center
A public trust hub on your own domain — policies, subprocessors, certifications, and a request intake that runs the statutory clock for you. Free to start.
Data Protection Officer
A named, registered DPO discharging Art. 37–39 duties — advice, monitoring, DPIA sign-off, and the supervisory-authority relationship. Priced from the DPO marketplace.
Cover & connections
Business Insurance
For U.S. companies only — professional indemnity, cyber, and D&O across all 50 states, one partner, one policy stack. Priced on your revenue, headcount, and risk profile.
Integrations
1,000+ apps across HR, ticketing, identity, and chat — Slack, Jira, Workday, Okta, BambooHR, NetSuite. Plus a REST API and webhooks for anything we haven't built yet.
From public page to insured.
These aren't a sequence you have to buy at once. Publish the trust hub first — it's free and it starts absorbing requests immediately. The officer, the integrations, and the cover phase in as the obligations arrive.
Privacy Center live
Trust hub on your domain, request intake open, clock running.
DPO appointed
Named officer matched, contact published, authority notified.
Integrations connected
Requests into Jira, alerts into Slack, sign-in through Okta.
Cover bound
PI, cyber, and D&O quoted against your actual risk profile.
Reporting on calendar
Request volumes, response times, and renewals in one review.
Trust comes first. The privacy center is the artefact every enterprise security review asks for, and the intake behind it is what stops access and deletion requests from rotting in a shared inbox. It's free at low volume, so there's no reason to wait.
The officer is a legal appointment, not a seat licence. Where Art. 37 applies you need a named person on the record — reachable, independent, and answerable to the supervisory authority. We match one from the DPO marketplace and publish the contact for you.
Cover and connections are the long tail. US insurance gets quoted when a contract or a board seat forces it. Integrations are included from day one — this stack is only useful if it lives where your team already works.
The trust two.
Publish, then appoint.
Most teams start here: a public privacy center that answers the security-review questionnaire and absorbs incoming requests, plus a named DPO once the obligation actually bites. Cover and integrations follow.
Run both with us · One point of contactWhat teams ask us first.
Why is this a separate pillar and not part of Compliance?
Because none of it is a representative appointment. Compliance is the set of mandates where a regulation names an EU-based entity and we are it. More is everything that sits alongside that: a public trust surface, an officer appointment, an insurance programme, and the plumbing. Different obligations, different buyers, same account team.
Do I need a DPO if I already have an EU representative?
They're different roles and one doesn't substitute for the other. The Art. 27 representative is the local point of contact for a company with no EU establishment. The Art. 37 DPO is an independent adviser who monitors your compliance internally — and Art. 38(6) forbids conflicts of interest, which is exactly why the same person can't credibly do both.
Is Privacy Center really free?
Yes, up to 10 requests a month — hosted hub, policy pages, subprocessor list, and intake. Plus is $57 / mo and Pro is $147 / mo when you need higher volume, custom domains, workflow routing, and the audit trail. No card to start.
Is the business insurance EU cover?
No — it's for U.S. companies only: professional indemnity, cyber, and D&O, written across all 50 states and priced in dollars. It's here because most of our customers are US companies expanding into Europe and would rather run one relationship than two. We don't broker EU-domiciled cover today.
How is the DPO priced?
From $897 / mo, but the real number comes from the DPO marketplace — officers list their own rates, and what you pay depends on the one you're matched with. Sector experience, language coverage, and how many hours a month you need all move the price. We'll show you the shortlist before you commit.
Do integrations cost extra?
No. Every integration is included with the product it connects to, on every plan — including the REST API and webhooks. If the app you need isn't on the list, the API covers it, and we'll build a native connector if enough customers ask.
Your trust layer, live.
30-minute call. We'll look at what you already publish, what your buyers keep asking for, and quote the gap — in writing.