Trust Center

Trust Center

Where your data lives, who touches it, and how we keep it safe.

← Back to homepage

Data residency

SetAIComply runs on Railway (EU Amsterdam) for all application services including the frontend, API, PostgreSQL database, and Redis cache. Stripe handles payments, Cloudflare delivers transactional email, and Anthropic powers AI generation. All customer data is hosted in the European Union (Amsterdam, Netherlands). Our non-EU sub-processors — Anthropic and Cloudflare (United States) — are used for AI generation and transactional email under EU Standard Contractual Clauses.

Data Processing Agreement

We offer a Data Processing Agreement on request. Download the template at DPA.

Security practices

  • Encryption at rest for all customer data
  • TLS 1.2+ in transit for every connection
  • Role-based access control and least-privilege internally
  • Tamper-evident audit log across sensitive actions
  • Documented incident response with 24h acknowledgement SLA
  • Regular dependency updates and automated vulnerability scans

Incident response

security@setaicomply.com · We respond within 24 hours.

Certifications status

Planned: ISO 27001 and SOC 2 Type II. Neither is active yet — we only claim what we actually hold.

GDPR

SetAIComply is GDPR-native. Full details in our Privacy Policy.