EU-only hosting
Production runs in EU regions. No US-only data residency. Sub-processor list available on request.
Trust
Procurement asks first. We answer first. Below: what runs today, what's in preparation, what we don't yet claim — and a one-business-day reply ready for your auditor.
Controls in place
Implemented today across the platform. Independent attestation programs are in preparation; we don't claim certifications we don't hold.
Production runs in EU regions. No US-only data residency. Sub-processor list available on request.
Data minimization, purpose limitation, retention, encryption in transit and at rest, DSAR export, right-to-erasure cascade.
Policy-based scoping plus a defense-in-depth Prisma extension. Tenant safety is a first-class platform concern.
Every API key has a CallerProfile. Reads and mutations are audited; mutation policies and budgets cap risk.
Every tenant-scoped mutation emits a lineage event. Combined with EnrichmentLog, you get one answer to 'where did this value come from?'.
Every exposed field declares sensitivity (PUBLIC / INTERNAL / RESTRICTED / PII / PHI / FINANCIAL) and a data category. CI rejects unclassified fields.
Compliance status
EU-hosted; DPA available; sub-processors disclosed.
Not yet certified. We do not claim ISO 27001 conformance.
Not yet attested. We do not claim SOC 2 attestation.
Compliance reviewers can answer 'what did the AI agent do?'.
Trust FAQ
Procurement
We respond within one business day. Send a request through the contact form.