Trust & security
ComplyEU is a compliance product. We hold ourselves to a higher standard than the tools we help you govern. This page is updated whenever our security posture changes.
Data residency
All customer data, OAuth tokens, evidence files, and database backups are stored in the European Union (Railway Frankfurt region, europe-west4). We do not replicate customer data to the United States or any non-EEA jurisdiction.
The single exception is AI classification: we send tool metadata only (name, description, vendor URL) to Anthropic in the US for risk-tier classification, under Standard Contractual Clauses. No personal data of your employees is sent to Anthropic.
Encryption
- In transit: TLS 1.3, HTTPS-only, HSTS.
- At rest: AES-256-GCM for OAuth access & refresh tokens; full-disk encryption on the production database.
- Passwords: Argon2id (memory-hard, configured at OWASP-recommended parameters).
- Session tokens: JWTs signed with HS256 and a per-deployment secret; 7-day rotation.
Access control
- Role-based access (owner, admin, member) enforced at every API endpoint.
- Multi-tenant isolation enforced at the database layer (every query is scoped by
org_id). - Admin actions, authentication events, and integration changes are written to an immutable audit log retained for 24 months.
- Production database access is limited to two named operators.
Sub-processors
We use the following sub-processors. We notify customers by email at least 14 days before adding or replacing one.
| Sub-processor | Purpose | Region | Transfer mechanism |
|---|---|---|---|
| Railway | Infrastructure (compute, database, networking) | EU (Frankfurt) | — |
| Anthropic | AI classification & policy generation (tool metadata only) | US | SCCs |
| Stripe | Payment processing | EU + US | SCCs |
| Resend | Transactional email | EU + US | SCCs |
| Workspace OAuth (when you connect Workspace) | EU + US | SCCs | |
| Microsoft | Microsoft 365 OAuth (when you connect M365) | EU + US | SCCs |
Backups & disaster recovery
- Daily automated database backups, encrypted, 30-day retention.
- RPO target: 24 hours. RTO target: 4 hours.
- Quarterly restore tests.
Incident response
- 72-hour personal-data breach notification commitment, in line with GDPR Article 33.
- Internal incident runbook covering containment, eradication, recovery, and post-mortem.
- Status updates published to [email protected] subscribers.
Compliance & certifications
- GDPR: compliant. See our Privacy Policy and DPA.
- EU AI Act: we don't deploy high-risk AI ourselves; the Claude classifier is used as a decision-support tool with a human-reviewable trail.
- SOC 2 Type I: on roadmap for 2026 Q4.
- ISO 27001: on roadmap for 2027.
Responsible disclosure
If you believe you've found a security issue, please email [email protected]. We commit to acknowledging within 48 hours and providing a remediation timeline within 7 days. We will not pursue legal action against good-faith researchers who follow responsible-disclosure norms.
Contact
- Security & vulnerability disclosure: [email protected]
- Privacy & data-subject requests: [email protected]
- Customer DPA, sub-processor inquiries: [email protected]