Trust

Security & Trust

Last updated June 13, 2026. A factual overview of how Fideria protects customer data and meets European compliance requirements.

Document
Data Processing Agreement
GDPR Article 28 template · PDF, 3 pages
Download DPA →
Data residency
EU · Frankfurt
Encryption
TLS 1.2+ · AES-256
Breach SLA
72h · GDPR Art. 33
What's true today

These controls are in production now. They are not roadmap items or aspirational statements.

Access control
  • SAML 2.0 SSO
  • Role-based access control
  • MFA for all production staff
  • Admin-gated database writes
Encryption & residency
  • TLS 1.2+ in transit
  • AES-256 at rest
  • EU data residency · Frankfurt
  • Daily encrypted backups
AI governance & data handling
  • Row-Level Security per organization
  • Your data not used to train models
  • 30-day deletion commitment
  • Article 17 & 20 rights in-product
Audit logging
  • Append-only per-organization log
  • Sign-in, roles, SSO, exports
  • Severity filtering
  • CSV export
Application security
  • Zod validation on every endpoint
  • Signed webhooks
  • Dependency & static analysis
  • RLS policy audits
Incident response & EU frameworks
  • 72-hour breach notification
  • On-call rotation
  • EU AI Act alignment
  • NIS2 alignment
Controls in detail
01AI governance & data handlingCustomer data is isolated, never used to train foundation models, and deletable on request.
  • Per-organization isolation enforced by Row-Level Security.
  • Customer data and prompts not used to train foundation models.
  • Deletion within 30 days; backups roll off within 35.
02Infrastructure & encryptionEU-hosted, encrypted in transit and at rest, with daily backups.
  • EU infrastructure operated by ISO 27001 / SOC 2 providers.
  • TLS 1.2+ in transit, AES-256 at rest, secrets in managed vault.
  • Daily encrypted backups with point-in-time recovery.
03Access controlSSO, role-based access, MFA for staff and least-privilege engineering.
  • SAML 2.0 SSO for enterprise; RBAC separated from profile data.
  • MFA enforced for all Fideria staff with production access.
  • Engineering access is time-bound and reviewed quarterly.
  • Org settings, roles, SSO and alerts restricted to admins at the database layer.
04Audit loggingAppend-only audit log for every security-relevant action, exportable as CSV.
  • Per-organization, append-only audit log.
  • Covers sign-in, role changes, SSO config, data export and deletion.
  • Admins can search, filter by severity and export as CSV.
05Application securityValidated inputs, signed webhooks, dependency scanning and continuous policy audits.
  • Zod validation on every server endpoint; bearer tokens validated server-side.
  • Webhook signatures verified with constant-time comparison.
  • Dependency scanning, static analysis and database linter on every release.
  • RLS policies and SECURITY DEFINER grants audited 13 June 2026, no critical findings open.
06Incident response & complianceOn-call rotation, 72-hour GDPR breach notice, and alignment with EU AI Act and NIS2.
  • On-call rotation with defined severity levels and response times.
  • Personal-data breach notification within 72h (GDPR Art. 33).
  • Post-incident reviews shared with affected customers.
  • Article 20 export and Article 17 deletion available in-product.
  • EU AI Act and NIS2 technical and organizational measures are in place.
Security is a posture, not a checkbox. We publish what's in place, what's aligned, and what's planned, and we don't pretend otherwise.
Fideria security posture
EU
Resident data
72h
Breach SLA
0
Training on your data
30d
Deletion window
Are you SOC 2, ISO 27001 or ISO 42001 certified?

Not yet. The controls above are implemented today. A SOC 2 Type II audit window, ISO 27001 certification and ISO 42001 AI management system alignment are all targeted for 2027. Ask us for the current state of specific controls if that's relevant to your review.

Sub-processors
A small, vetted list for hosting, authentication, email and AI inference. Customers receive 30 days' notice before any material change.
View list
Responsible disclosure
Security issues to security@fideria.ai. Acknowledged within two business days. No legal action for good-faith research.
Report an issue
Documentation on request
DPA, sub-processor list, CAIQ-Lite, independent penetration test scheduled before first production deployment, and architecture overview available to enterprise customers.
Request docs