Data residency
EU · Frankfurt
Encryption
TLS 1.2+ · AES-256
Breach SLA
72h · GDPR Art. 33
What's true today
These controls are in production now. They are not roadmap items or aspirational statements.
Access control
- SAML 2.0 SSO
- Role-based access control
- MFA for all production staff
- Admin-gated database writes
Encryption & residency
- TLS 1.2+ in transit
- AES-256 at rest
- EU data residency · Frankfurt
- Daily encrypted backups
AI governance & data handling
- Row-Level Security per organization
- Your data not used to train models
- 30-day deletion commitment
- Article 17 & 20 rights in-product
Audit logging
- Append-only per-organization log
- Sign-in, roles, SSO, exports
- Severity filtering
- CSV export
Application security
- Zod validation on every endpoint
- Signed webhooks
- Dependency & static analysis
- RLS policy audits
Incident response & EU frameworks
- 72-hour breach notification
- On-call rotation
- EU AI Act alignment
- NIS2 alignment
Controls in detail
Security is a posture, not a checkbox. We publish what's in place, what's aligned, and what's planned, and we don't pretend otherwise.
EU
Resident data
72h
Breach SLA
0
Training on your data
30d
Deletion window
Are you SOC 2, ISO 27001 or ISO 42001 certified?
Not yet. The controls above are implemented today. A SOC 2 Type II audit window, ISO 27001 certification and ISO 42001 AI management system alignment are all targeted for 2027. Ask us for the current state of specific controls if that's relevant to your review.
Sub-processors
A small, vetted list for hosting, authentication, email and AI inference. Customers receive 30 days' notice before any material change.
Responsible disclosure
Security issues to security@fideria.ai. Acknowledged within two business days. No legal action for good-faith research.
Documentation on request
DPA, sub-processor list, CAIQ-Lite, independent penetration test scheduled before first production deployment, and architecture overview available to enterprise customers.