Security & Trust

Your compliance data, kept in Europe

You are trusting us with the evidence that proves you follow the law. Here is how we protect it, in plain terms your DPO and security team can check.

EU-sovereign hosting

We build and host everything on European infrastructure we operate ourselves. Your data is stored and processed only in the EU, with no AWS, Azure, or GCP in the path and nothing transferred outside the Union.

Outside the US CLOUD Act

We are a Swiss company with no US parent, so the US CLOUD Act does not reach us. No foreign authority can compel us to hand over the regulatory records you keep here.

Strong authentication

Sign in with email and password, Google, or enterprise SSO over SAML and OIDC. Add TOTP two-factor or hardware passkeys. Passwords are stored only as salted bcrypt hashes, never in plain text.

Tenant isolation

Every record is scoped to its organisation and every request is checked against the tenant it belongs to. Our end-to-end test suite includes explicit cross-tenant isolation checks that run on every release.

Local NLP inference

PII and GDPR Article 9 special category data detection (health, religion, politics, trade union, sexual orientation, racial origin) runs on in-cluster models. No text is sent to external AI providers. The Presidio Analyzer and GLiNER zero-shot NER both execute inside our European infrastructure.

Encryption & access control

All traffic is served over TLS. Role-based access (admin, editor, viewer) and optional department scoping keep access on a need-to-know basis, and API keys can be issued and revoked per integration.

Accountability & monitoring

Security-relevant actions are written to an immutable audit trail. Request rate limiting, structured logging, and continuous monitoring help us detect and respond to unusual activity.

Cryptographic chain of custody

Every regulatory document exported from the Business tier includes an X.509 cryptographic server seal and is recorded in an immutable database hash log. If a document is altered outside the platform, the seal breaks, ensuring your compliance record remains strictly verifiable.

We hold ourselves to the frameworks we sell

It would be strange to run a compliance platform that wasn't run compliantly. The same standards the product helps you meet shape how we operate.

GDPR

Data protection by design, data subject rights, breach handling, and records of processing built into the product itself.

ISO/IEC 27001

We operate our ISMS around the ISO 27001 control set, and the platform helps you map the same controls.

EU AI Act & DORA

The same frameworks we help customers evidence inform how we run our own governance and operational resilience.

We describe our practices honestly and do not claim certifications we do not hold. If you need specific documentation for a vendor assessment, contact us and we will help.

Responsible disclosure

Found a vulnerability? We want to hear about it. Report it privately and we will acknowledge your message, investigate, and keep you updated. Please give us a reasonable window to fix issues before disclosing them publicly.

info@eurocompliant.com

Questions from your security team?

We are happy to walk through our setup, answer a vendor questionnaire, or talk through your data-residency requirements.