GDPRSOC 2Multi-tenant
Security & Compliance
Principles implemented in the code, not just claimed. Click each tab to see the details.
GDPR — European regulation
Built for European clients. Every data subject right is implemented end-to-end, from intake to erasure.
- Right of access — export your full data in one click
- Right to erasure — delete your account and all traces within 30 days
- Right to portability — standard JSON/CSV export
- Explicit consent tracking on all data capture points
- Data minimization — only what's needed, retained only as long as needed
- DPO contact and audit log available on request
SOC 2 — Controls framework
Aligned with the SOC 2 Trust Services Criteria: security, availability, processing integrity, confidentiality.
- Access controls — role-based, least privilege, quarterly reviews
- Change management — peer review, automated tests, audit trail
- Incident response — 24/7 on-call, documented playbooks
- Vendor management — third parties assessed and monitored
- Availability monitoring — uptime SLO, alerting, redundancy
- Annual third-party pen test (available under NDA)
Encryption — Data protected at every layer
Data is encrypted in transit and at rest. Keys are isolated per tenant to prevent cross-client access.
- TLS 1.3 for all traffic, HSTS enforced
- AES-256 encryption at rest for databases and backups
- Keys managed in an isolated KMS, rotated regularly
- Secrets stored in an encrypted vault, never in code
- Full-disk encryption on all infrastructure nodes
Multi-tenant — Isolation by design
Multi-tenant architecture with strict per-client data isolation. No client can ever access another client's data.
- Row-level security on every database query
- Tenant ID enforced at the API gateway and database layers
- Separate encryption keys per tenant
- Audit logging of every cross-tenant attempt (blocked + alerted)
- Option for dedicated infrastructure on Enterprise tier