Skip to main content
Security, Audit & Data Residency

Built so you can prove what happened.

EU hosting, tenant isolation at the database layer, and a tamper-evident audit log that an auditor can verify.

Your data stays in the EU

The platform runs on EU infrastructure, with EU-resident providers for identity, email, and storage. Every sub-processor is listed publicly, and none is added without notice.

Tenant isolation in the database, not just the app

Each tenant gets its own database schema, and every request runs inside its tenant's context — enforced at the database layer, with row-level security on the few shared tables. A query without a tenant context reads and writes nothing. Isolation isn't a setting in the application code that a bug could skip.

An audit log that resists tampering

Append-only at the database level — the application can't update or delete it. Each record is hash-chained to the previous one, and a verifier checks the entire chain every day. The chain heads are cold-exported to object-locked EU storage daily, and records are kept for seven years — ten under MaRisk.

Personal data handled deliberately

PII is tagged at the column level. A masking layer pseudonymizes it; reversing that takes dual approval and is visible to the Works Council on a built-in delay. Personal-data access is logged on its own channel.

Segregation of duties, enforced in code

The platform stops one person from holding incompatible roles — submitting and approving the same change, or being both the responder and the regulatory reporter on the same major incident.

Access, provisioned and governed

Single sign-on and SCIM provisioning through an EU-resident identity provider, multi-factor authentication required on sensitive roles, and scoped personal access tokens for the REST API.

The audit chain

Every record commits the one before it.

The log is append-only at the database layer and hash-chained per tenant. A verifier re-checks the whole chain daily and cold-exports it to object-locked EU storage. Alter one record and the math stops matching — visibly.

Audit logChain verified · hourly
TimeEventHash
09:41:02Alert — p99 latency > 800 ms on api-gateway-eu9e2f…a7
09:43:10Acknowledged · raised to P1c4b1…3d
09:44:55CHG-118 approved · segregation-of-duties verified7f3a…9e
09:52:31CI pg-primary-eu modifieda1d8…02
10:00:00Chain re-verified · cold-exported to EU object-lockb2e0…5c
each record commits the previous record’s hash — altering one breaks the chain

Certifications

TENSORis not yet ISO 27001 or SOC 2 certified. We're building toward certification as the platform matures, and we won't claim a badge we don't hold. In the meantime, the security pack documents our architecture, controls, and sub-processors — request it and judge the substance directly.

Responsible disclosure

If you discover a security vulnerability, report it to security@itsmx.eu. We respond within 48 hours.

Request the TENSOR security pack.

DPA, sub-processor list, architecture overview, and answers to your security questionnaire.