Resources
SOC 2 Type 2 Report
Independent audit of our security controls and operational effectiveness.
PCI DSS 4.0 (SAQ-A)
Payment Card Industry Data Security Standard compliance documentation. Ensures secure handling of cardholder data and adherence to payment processing requirements from 3rd party payment providers we use.
Cybersecurity Insurance
Coverage details and policy information for our insurance, including cyber liability protection.
Penetration Testing Report
Third-party security assessment results from our latest penetration testing. Identifies vulnerabilities and documents remediation actions taken.
Privacy Policy
Our commitment to data protection and privacy practices. Details how we collect, use, and safeguard personal information in compliance with applicable regulations.
System Status Page
Real-time operational status and historical uptime data for our services. Includes scheduled maintenance windows and incident notifications.
Terms and conditions
Legal agreement governing the use of our services. Outlines user responsibilities, service limitations, and dispute resolution procedures.
Acceptable use policy
Access control and termination policy
Business continuity and disaster recovery plan
FAQs
Subprocessors
Okta Inc. (Okta Workforce Identity & Auth0)
Used for secure identity and access management across our organization, and external identity and access management across our services.
Google Cloud Platform (Google LLC, USA)
Cloud infrastructure, hosting, data storage, and AI/ML processing
SendGrid (Twilio Inc., USA):
Transactional email delivery to travelers
Stripe (Stripe Inc., USA)
Payment processing for traveler transactions
Mollie (Mollie B.V., Netherlands)
Payment processing for traveler transactions
Zendesk (Zendesk Inc., USA)
Customer support platform, storage and processing of traveler support interactions
Zapier (Zapier Inc., USA)
Workflow automation platform, processing of traveler personal data during automated data transfers between systems
Ninja Partners, LLC
Traveler support services operating under Sherpa's instructions within Sherpa's systems
Team Karimganj Technology Solutions Private Limited
Traveler support services operating under Sherpa's instructions within Sherpa's systems
Monitoring
Compliance
GDPR
SOC 2 Type 2
PCI
Trusted by
Custom section title
Custom section description