Trust
Security & data protection.
A compliance product should hold itself to the standard it asks of others. Here is how we handle your data — plainly, and without overstating our stage.
Data hosted in the EU
Your workspace data is stored on EU-based cloud infrastructure. Keeping European regulatory data in Europe is a deliberate default, not an add-on.
Tenant isolation
Each workspace is isolated at the database level with row-level security, so an account can only ever read and write its own records. Multi-tenant separation is enforced by the data layer, not just the application.
Encryption in transit and at rest
All traffic is served over HTTPS, and data is encrypted at rest by our infrastructure provider.
Authentication & access
Access is authenticated per user and scoped to the workspace. Sensitive keys never reach the browser; the front end uses a public, restricted key only.
You control your data
You can export your records and request deletion of your workspace and its data. We do not sell personal data, and we do not use your compliance data to train models.
Tamper-evident audit trail
Evidence and sign-offs are recorded in an append-only, hash-chained audit trail, so the compliance record itself is verifiable.
We rely on a small number of established infrastructure providers to run the service. A current list is available on request.
- Cloud database & authManaged EU-region Postgres with row-level security (Supabase).
- AI featuresWhere AI assistance is used, requests go to a hosted large-language-model provider; sensitive fields are minimised. This is optional and clearly indicated.
- Hosting & CDNStatic site and application delivery over a global CDN with automatic TLS.
Euridium is in beta. We apply the security practices above and align our data handling with the GDPR. We do not currently hold formal third-party certifications such as SOC 2 or ISO/IEC 27001, and we will not claim badges we have not earned — that would contradict the entire premise of the product. Independent certification is on our roadmap; until then, we are transparent about exactly where we stand and will share a detailed security overview on request.
Questions about security or data?
We are happy to walk your team through our architecture, data flows and processing terms.