Trust Center
Full transparency about how we protect your data, who we work with, and how we maintain compliance — so you can focus on your own obligations.
Security Commitments
EU Data Residency
All customer data stored exclusively in AWS eu-west-1 (Ireland) and eu-central-1 (Frankfurt). Never leaves the EU.
SOC 2 Type II
Third-party audit in progress. Report expected Q4 2026. Controls audited by an AICPA-accredited firm.
No AI Training
Customer data and documents are never used to train or fine-tune any AI model. Full stop.
AES-256-GCM Encryption
All data encrypted at rest with per-tenant keys. Transit encrypted with TLS 1.3 minimum.
Customer-Managed Keys (BYOK)
Enterprise customers can bring their own AWS KMS, Azure Key Vault, or GCP KMS keys.
ISO 27001
ISMS implementation underway. Certification audit planned Q1 2027.
Compliance Roadmap
GDPR Article 32 Compliance
Encryption at rest, access controls, and audit logging implemented and verified.
NIS2 Controls Assessment
Internal gap assessment against NIS2 requirements completed. Controls mapped.
DORA Alignment
ICT risk management and incident reporting procedures documented and tested.
BYOK / CMK Launch
Customer-managed encryption keys available for Enterprise and Strategic tier customers.
SOC 2 Type II Audit
Third-party audit in progress. Report expected Q4 2026.
Dedicated Infrastructure Tier
Isolated single-tenant infrastructure available for regulated customers.
ISO 27001 Certification
ISMS implementation and external certification audit.
Subprocessors
All subprocessors are under signed DPAs. We notify customers 30 days before adding new ones.
| Subprocessor | Purpose | Data Processed | Location | DPA Status |
|---|---|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure hosting | All platform data | EU (Frankfurt, Ireland) | Signed |
| Vercel | Frontend hosting & CDN | Static assets only | EU edge locations | Signed |
| Anthropic | AI-powered compliance analysis | Document text (no PII extracted) | US (with EU SCCs) | Signed |
| Stripe | Payment processing | Billing information only | EU | Signed |
| Resend | Transactional email | Email addresses, notification content | EU | Signed |
| Sentry | Error monitoring | Error logs (PII redacted) | EU | Signed |
Last updated: 14 September 2026. We notify customers 30 days before adding new subprocessors.
Security Documents
Staff Data Access Controls
How we protect customer data from internal access — zero standing access architecture.
Data Processing Agreement
Standard DPA template for enterprise customers. Legally reviewed for GDPR compliance.
Tenant Isolation Architecture
Technical overview of RLS policies, encryption boundaries and isolation layers.
Penetration Test Summary
Latest third-party security assessment results (available under NDA for Enterprise).
Questions about security?
Our security team is available for due diligence calls, questionnaire support, and enterprise security reviews.
Contact Security Team