Last updated: 5 October 2026
Our position
We are not SOC 2 certified. We will pursue SOC 2 Type I when a customer contract requires it. We answer security questionnaires on request: email euassuranceai@souravamseekar.com.
Controls
- EU hosting
- Production runs on Oracle Cloud in the EU (Frankfurt/Amsterdam).
- TLS everywhere
- All traffic is encrypted in transit through Cloudflare; the API is not exposed to the internet.
- Encryption at rest
- Block volumes are encrypted by default. Backups are encrypted with age before upload to an EU-jurisdiction bucket.
- Tenant isolation
- Every query is scoped to the caller's workspace, and isolation is covered by automated tests.
- Tamper-evident audit ledger
- Audit events are hash-chained, with a verification endpoint.
- Signed evidence packs
- Packs are signed with RS256 and verifiable against our public JWKS. How to verify a pack.
- MFA
- Multi-factor authentication on every administrative account (cloud, DNS, code hosting, payments).
- Dependency and secret scanning
- Dependabot updates and gitleaks secret scanning on every change.
- Rate limiting
- Sign-in, sign-up and public endpoints are rate limited.
- No LLM on your content
- No large language model processes customer content by default.
- Backups
- Nightly backups with a monthly restore drill. Recovery point objective 24 hours, recovery time objective 4 hours.
Subprocessors
See the subprocessors list and the DPA.
Report a vulnerability
Email euassuranceai@souravamseekar.com. Please give us 90 days to fix an issue before publishing it, and do not access other customers' data. Our security.txt has the same details.