SOC 2 Type II, GDPR, AES-256 at rest and TLS 1.3 in transit. Data in the EU. Contract legal review.
Annual independent audit. Report available under NDA.
GDPR compliantAssigned DPO, signable DPA, subject rights fulfilled in under 30 days.
AES-256 at rest, TLS 1.3 in transit. Keys managed via HSM.
EU data residencyVercel Enterprise EU infrastructure. No replication outside EU without consent.
Every action logged: user, IP, timestamp, responsible agent. Exportable.
Backups + DRDaily encrypted backups. RPO 1h, RTO 4h. Tested disaster recovery plan.
We share the SOC 2 Type II report under NDA. We can also sign a DPA and review contract clauses.
SOC 2 Type II · GDPR · Data residency EU