Security and data protection
Encryption at rest
All user data is encrypted at rest with AES-256 at disk level. Backups are encrypted too.
Encryption in transit
All communication runs over HTTPS with TLS 1.2+ (TLS 1.3 preferred). Insecure HTTP connections are redirected automatically.
EU data residency
Customer data is processed and stored exclusively in data centres located in the European Union, in line with GDPR Art. 46.
Access control
Multi-tenant architecture with strict per-client isolation. Every request is authenticated and authorised through dedicated middleware. 2FA is available.
Continuous monitoring
Errors and anomalies are monitored in real time. Access logs are retained for 90 days for forensic analysis.
Data deletion
You can export or delete your data at any time from the GDPR panel. Requests are processed within 30 days.
Vulnerability disclosure
If you have found a security vulnerability in Eniteo AI, we ask you to report it responsibly before making it public. Write to [email protected] with a detailed description of the problem.
We undertake to respond within 48 working hours, and to ship a fix within 14 days for critical vulnerabilities. We take no legal action against anyone reporting in good faith.
Sub-processors
We use a limited number of third-party providers to deliver the service. The current list is on the Sub-processors page. All of them are GDPR-compliant and have signed DPAs.
SOC 2 — roadmap
We are currently working towards SOC 2 Type II certification. If you are an enterprise customer who needs specific compliance documentation, write to [email protected].