← Eniteo

Security and data protection

Updated: August 2026 · Read the DPA →

🇪🇺 EU servers 🔒 GDPR Art. 28 🛡️ TLS 1.3 encryption 📋 SOC 2 (on the roadmap)
🔐

Encryption at rest

All user data is encrypted at rest with AES-256 at disk level. Backups are encrypted too.

🌐

Encryption in transit

All communication runs over HTTPS with TLS 1.2+ (TLS 1.3 preferred). Insecure HTTP connections are redirected automatically.

🇪🇺

EU data residency

Customer data is processed and stored exclusively in data centres located in the European Union, in line with GDPR Art. 46.

🔑

Access control

Multi-tenant architecture with strict per-client isolation. Every request is authenticated and authorised through dedicated middleware. 2FA is available.

🔍

Continuous monitoring

Errors and anomalies are monitored in real time. Access logs are retained for 90 days for forensic analysis.

🧹

Data deletion

You can export or delete your data at any time from the GDPR panel. Requests are processed within 30 days.

Vulnerability disclosure

If you have found a security vulnerability in Eniteo AI, we ask you to report it responsibly before making it public. Write to [email protected] with a detailed description of the problem.

We undertake to respond within 48 working hours, and to ship a fix within 14 days for critical vulnerabilities. We take no legal action against anyone reporting in good faith.

Sub-processors

We use a limited number of third-party providers to deliver the service. The current list is on the Sub-processors page. All of them are GDPR-compliant and have signed DPAs.

SOC 2 — roadmap

We are currently working towards SOC 2 Type II certification. If you are an enterprise customer who needs specific compliance documentation, write to [email protected].