Idukki
Back to security
Procurement bundle

Request the DPA + security bundle.

One ZIP, one UK business day, no sales call. Routed straight to legal. The bundle is the procurement-ready version of our security page — the same facts, in the form your team can actually sign.

  • DPA + SCCs

    Standard Contractual Clauses for UK + EU + DPDP. Pre-signed, redline-friendly Word doc.

  • Sub-processor register

    Every vendor that touches customer data, what they process, the legal basis and the region.

  • SIG-Lite

    Filled in. Refreshed at the start of every quarter. Maps to the SIG full questionnaire on request.

  • Penetration test summary

    Executive summary from our last independent annual test. Full report under NDA.

  • SOC 2 audit progress note

    Where we are in the Type I audit window, what is in scope, target attestation date.

  • MSA redlines

    The standard MSA + the variant we sign with regulated brands. Legal does not need to re-write from scratch.

What it is not

  • Not a sales-disqualifier. Plenty of customers request this on day one — we treat it as a standard step.
  • Not gated behind a discovery call. The form goes to the security inbox, not the sales pipeline.
  • Not a sub for the full SOC 2 Type II audit (in progress for 2026). When the attestation lands, the bundle is updated automatically.

Send it to

Your security or procurement team

We email the bundle directly. No public download link, no tracking pixel.

Cloudflare bot-protection

No spam. Unsubscribe anytime. We never sell your data.

Already an Idukki customer? You can also pull the latest bundle from the workspace under Settings → Compliance.

Plain-English answers

4-min setup1,400+ brands37 KB runtime5.0 G2

Security review

Need our SOC 2 report or DPA?

Available under NDA in minutes. Plus a fully-prefilled vendor security questionnaire (CAIQ + SIG-Lite).

  • No credit card
  • Cancel anytime
  • SOC 2 + GDPR

Where Idukki ships

Same data model. Every surface a shopper meets.