Security & compliance
Your data is our top priority.
The platform reads your company's most sensitive numbers. Here is exactly how they are protected — encryption, residency, access, and what happens if something goes wrong.
Six layers, no exceptions
Encryption
Encrypted in transit and at rest
- AES-256 at rest, TLS 1.3 in transit
- Keys managed in a dedicated KMS
- Automatic key rotation
Residency
Your data stays in the EU
- All production data hosted in EU regions
- No transfer outside the EEA
- Sub-processors listed in the DPA
Privacy
GDPR and CCPA, in writing
- DPA available to every customer
- Data-subject rights honored end to end
- Deletion on request, verified
Access control
The right people, nothing more
- SSO via SAML 2.0 and OIDC
- MFA mandatory for all accounts
- Granular roles with full audit logs
Monitoring
Watched continuously
- Weekly vulnerability scans
- Annual third-party penetration tests
- 99.9% uptime SLA
Incident response
If something goes wrong
- Notification within 72 hours
- 24/7 response team
- Daily backups, 90-day retention
Need the detail your security team asks for?
The Security Whitepaper covers architecture, encryption, sub-processors, and incident response in full.