Logo
EU Data Residency Active

Trust Center

Full transparency about how we protect your data, who we work with, and how we maintain compliance — so you can focus on your own obligations.

Security Commitments

Active

EU Data Residency

All customer data stored exclusively in AWS eu-west-1 (Ireland) and eu-central-1 (Frankfurt). Never leaves the EU.

In Progress

SOC 2 Type II

Third-party audit in progress. Report expected Q4 2026. Controls audited by an AICPA-accredited firm.

Active

No AI Training

Customer data and documents are never used to train or fine-tune any AI model. Full stop.

Active

AES-256-GCM Encryption

All data encrypted at rest with per-tenant keys. Transit encrypted with TLS 1.3 minimum.

Active

Customer-Managed Keys (BYOK)

Enterprise customers can bring their own AWS KMS, Azure Key Vault, or GCP KMS keys.

Planned

ISO 27001

ISMS implementation underway. Certification audit planned Q1 2027.

Compliance Roadmap

Q1 2025

GDPR Article 32 Compliance

Complete

Encryption at rest, access controls, and audit logging implemented and verified.

Q3 2025

NIS2 Controls Assessment

Complete

Internal gap assessment against NIS2 requirements completed. Controls mapped.

Q1 2026

DORA Alignment

Complete

ICT risk management and incident reporting procedures documented and tested.

Q2 2026

BYOK / CMK Launch

Complete

Customer-managed encryption keys available for Enterprise and Strategic tier customers.

Q3 2026

SOC 2 Type II Audit

In Progress

Third-party audit in progress. Report expected Q4 2026.

Q4 2026

Dedicated Infrastructure Tier

Planned

Isolated single-tenant infrastructure available for regulated customers.

Q1 2027

ISO 27001 Certification

Planned

ISMS implementation and external certification audit.

Subprocessors

All subprocessors are under signed DPAs. We notify customers 30 days before adding new ones.

SubprocessorPurposeData ProcessedLocationDPA Status
Amazon Web Services (AWS)Cloud infrastructure hostingAll platform dataEU (Frankfurt, Ireland) Signed
VercelFrontend hosting & CDNStatic assets onlyEU edge locations Signed
AnthropicAI-powered compliance analysisDocument text (no PII extracted)US (with EU SCCs) Signed
StripePayment processingBilling information onlyEU Signed
ResendTransactional emailEmail addresses, notification contentEU Signed
SentryError monitoringError logs (PII redacted)EU Signed

Last updated: 14 September 2026. We notify customers 30 days before adding new subprocessors.

Security Documents

Questions about security?

Our security team is available for due diligence calls, questionnaire support, and enterprise security reviews.

Contact Security Team