§01
Data residency
All tenant data — connector credentials, raw extracts, the warehouse, backups, and audit logs — lives in EU data centres: primary capacity in Falkenstein, Germany and encrypted backups in Helsinki, Finland. No tenant byte ever leaves EU territory or transits a US-headquartered cloud.
- Primary: Falkenstein, Germany (Hetzner)
- Backup: Helsinki, Finland (Hetzner)
- No AWS · no Azure · no Google Cloud
- Operated by Custodea B.V., Amsterdam
§02
Encryption
Data is encrypted at rest with LUKS-managed AES-256 on each storage volume and encrypted in transit with TLS 1.3. Connector credentials are wrapped a second time with a KMS-style envelope; the unwrapping key never leaves the warehouse cluster.
- AES-256 at rest, TLS 1.3 in transit
- Per-tenant credential envelope keys
- Database backups encrypted with separate keys
§03
Access control
You hold the keys. Credentials for each tool — your BI dashboard, dbt, your auditor's read-only access — are minted in Settings and revoked the same way.
- Per-tool credentials you mint and revoke
§04
What we won't do
We don't sell or share your data. We don't train models on it. We won't add a US sub-processor to make a feature ship faster. The product roadmap exists downstream of these constraints, not the other way around.
§05
Compliance & audits
We're GDPR-compliant by default and sign a DPA with every customer at sign-up. ISO/IEC 27001 is planned for Q4 2026 and SOC 2 Type II is planned for 2027. The internal control framework is in place; what's still happening is the third-party audit.
- GDPR — compliant; DPA signed at sign-up
- ISO/IEC 27001 — planned for Q4 2026
- SOC 2 Type II — planned 2027
§06
Incident response
We aim for a 1-hour internal acknowledgement and a 24-hour customer notification on any confirmed security incident affecting tenant data.