Encryption
TLS 1.2+ in transit, AES-256 at rest. Keys rotate on a fixed schedule and are held in a managed KMS, separate from the data.
Every claim below is something we can show, not just tell. Run your own diligence, or ask and we will walk you through it.
TLS 1.2+ in transit, AES-256 at rest. Keys rotate on a fixed schedule and are held in a managed KMS, separate from the data.
Role-based access, SSO and SCIM on request, MFA enforced internally. Production access is time-boxed, approved and logged per session.
You choose the region at contract. Customer data stays in it, including backups. Screening can run against hashed identifiers where policy forbids sending names.
Retention is set per jurisdiction, five to ten years where required. Deletion requests are honoured within 30 days, subject to statutory holds.
Every read of a customer record is logged with actor and time. Alerting runs on anomalous access; logs are retained independently of the platform.
99.9% availability target, multi-zone deployment, tested restores. RTO 4 hours, RPO 15 minutes, exercised twice a year.
Frankfurt and Dublin.
London.
Istanbul, under KVKK.
Hosting and storage. Contracted region: EU.
Alerts and notifications. Contracted region: EU.
Diagnostics, no customer records. Contracted region: EU.
Ticketing, on request only. Contracted region: EU.