Built compliant. Hosted in the EU. Audited end to end.
Our architecture is designed to meet the same regulatory standards we help our customers comply with.
In progress
SOC 2 Type 1
Audit underway. Target completion: Q4 2026.
Planned
ISO 27001
Scope defined. Target audit: Q1 2027.
Available
GDPR DPA
Data Processing Agreement available on request for all customers.
EU data residency. End-to-end.
All customer data is stored and processed exclusively on Google Cloud Platform, Frankfurt region (europe-west3). No data crosses EU borders. Sub-processor list is available on request.
Role-based access
MLRO, Compliance Officer, Read-only Auditor, Administrator. Granular permission model per module.
SSO via SAML / OIDC
Integrate with your existing identity provider (Okta, Azure AD, Google Workspace) on Growth and Enterprise tiers.
Audit trail
Every administrative action — permission changes, exports, configuration edits — is logged with timestamp and user identity.
Session management
Configurable session timeout. Forced re-authentication on sensitive operations (export, permission change).
4 hours
Acknowledgement SLA
All severity levels — working hours and out-of-hours.
72 hours
Incident report
Aligned with DORA's own incident reporting standard — we live the framework we sell.
100%
Breach notification
GDPR Article 33 notification to supervisory authority within 72 hours of becoming aware.
Have specific security questions?
Book a call with our team. We'll walk through our architecture, sub-processor list, and any specific compliance requirements your security team has.