- Hosting and residency
- Google Cloud, region europe-west3 (Frankfurt). All customer data is processed and stored within the European Economic Area.
- Encryption
- TLS 1.3 in transit. AES-256 at rest, including database storage and backups. Customer-managed encryption keys available on Enterprise.
- Access controls
- Production access is restricted to named personnel, requires multi-factor authentication, and is logged. Access reviews are performed quarterly. Customer data is accessed only by support personnel working on an active customer ticket, with all access logged.
- Audit logs
- Every screening action is logged with user, timestamp, inputs, and the returned evidence file. Logs are available to customer administrators on request. API-level audit log access is included on Intelligence and Enterprise tiers.
- Data retention
- Evidence files and screening history are retained for the active contract term. On termination, customers choose between secure deletion within 30 days or extended retention for regulatory archival up to 7 years, contracted separately. Operational logs are retained for 12 months.
- Data Processing Agreement
- A GDPR-compliant DPA is provided to all customers during contract negotiation. Standard Contractual Clauses are executed where applicable. Available for review before signing.
- Incident response
- Security incidents affecting customer data are disclosed to affected customers within 72 hours of confirmed discovery, with preliminary details and continuing updates until resolution.
- Compliance posture
- Strelux operates to SOC2 Type II control principles. Formal SOC2 Type I observation period begins Q1 2027. ISO 27001 certification is on the 2027 roadmap.