Skip to main content

SSecurity ledger

Enterprise-grade security with EU data residency.

Treda is built on the principle that compliance infrastructure must itself be compliant. Your AI system data never leaves the EU.

CCertifications

Compliance certifications.

Active

GDPR Compliant

All data processing operations

Since founding

Active

EU AI Act Self-Assessment

Treda platform AI components

Since launch

In Progress

ISO 27001:2022

ISMS for all operations

Target Q3 2026

Planned

SOC 2 Type II

Security, availability, confidentiality

Target Q1 2027

RFrameworks

Regulatory compliance frameworks.

GDPR

Fully Compliant

Regulation (EU) 2016/679

All personal data processing within Treda is governed by the EU General Data Protection Regulation (Regulation (EU) 2016/679). We maintain Records of Processing Activities (ROPA), Data Protection Impact Assessments (DPIAs), and support Data Subject Access Requests (DSARs).

  • Data Processing Agreement (DPA) available for all customers
  • Standard Contractual Clauses (SCCs) for any non-EEA data transfers
  • Privacy Shield successor framework compliance
  • Annual DPIA reviews for high-risk processing operations

EU AI Act

Self-Compliant

Regulation (EU) 2024/1689

Treda itself is a compliance tool, and we practice what we preach. Our platform is classified under the EU AI Act and we maintain full technical documentation, conformity assessments, and incident reporting for our own systems.

  • Self-hosted classification and conformity assessment
  • Technical documentation per Annex IV for our own AI features
  • Article 14 human oversight compliance for automated decision features
  • Article 62 incident reporting pipeline for our platform

ISO 27001

In Progress

ISO/IEC 27001:2022

We are pursuing ISO/IEC 27001:2022 certification for our Information Security Management System (ISMS). This complements our existing security controls and provides third-party validation of our security posture.

  • ISMS scope: all cloud infrastructure and development processes
  • Statement of Applicability (SoA) covering all 93 controls
  • Internal audits completed, external certification audit scheduled
  • Integration with EU AI Act security requirements (Article 15)

AControls

Security controls & infrastructure.

Encryption

  • AES-256 encryption at rest for all stored data (TLS 1.3 in transit)
  • Customer-managed encryption keys (CMEK) via Google Cloud KMS
  • Separate encryption keys per tenant with automatic rotation every 90 days
  • End-to-end encryption for sensitive compliance audit logs

Access Control

  • Role-Based Access Control (RBAC) with principle of least privilege
  • SAML 2.0 / OIDC SSO integration (Okta, Azure AD, Google Workspace)
  • Multi-factor authentication (MFA) enforced for all admin accounts
  • Session management with configurable timeout and device tracking

Audit Logging

  • Immutable audit trail for all data access and modifications
  • Tamper-evident logging with cryptographic hash chains
  • Full API request/response logging with PII redaction
  • Audit log retention: 7 years (configurable per compliance requirement)

Infrastructure

  • Hosted exclusively on EU-based data centers (Frankfurt, Dublin, Paris)
  • SOC 2 Type II compliant cloud providers (AWS eu-central-1, GCP europe-west3)
  • Network isolation with VPC, private subnets, and WAF protection
  • Automated vulnerability scanning and penetration testing (quarterly)

Data Residency

  • Zero cross-border data transfers outside EU/EEA by default
  • GDPR-compliant data processing in certified EU facilities only
  • Data residency verification with geographic binding for all storage
  • Member state-specific data hosting available on request

Identity & Access

  • SCIM 2.0 automated user provisioning and deprovisioning
  • Just-in-time access with time-limited elevated privileges
  • Privileged Access Management (PAM) for infrastructure access
  • Quarterly access reviews with manager attestation

Data Residency Guarantee

Treda guarantees that all customer data remains within the European Economic Area (EEA) at all times. We operate exclusively from EU-based data centers:

  • Primary: AWS eu-central-1 (Frankfurt, Germany)
  • Secondary: GCP europe-west3 (Frankfurt, Germany)
  • Disaster Recovery: AWS eu-west-1 (Dublin, Ireland)
  • Backup: Azure West Europe (Netherlands)

Incident Response

Our incident response process follows the NIST Cybersecurity Framework and complies with GDPR Article 33 breach notification requirements:

  • 24/7 on-call security team with 15-minute response SLA
  • Automated threat detection with SIEM and behavioral analysis
  • GDPR 72-hour breach notification commitment
  • Customer notification within 4 hours of confirmed breach
Under continuous review

Need a security assessment?

Request our full security whitepaper, SOC 2 readiness report, or schedule a technical deep-dive with our security engineering team.