SSecurity ledger
Enterprise-grade security with EU data residency.
Treda is built on the principle that compliance infrastructure must itself be compliant. Your AI system data never leaves the EU.
CCertifications
Compliance certifications.
GDPR Compliant
All data processing operations
Since founding
EU AI Act Self-Assessment
Treda platform AI components
Since launch
ISO 27001:2022
ISMS for all operations
Target Q3 2026
SOC 2 Type II
Security, availability, confidentiality
Target Q1 2027
RFrameworks
Regulatory compliance frameworks.
GDPR
Fully CompliantRegulation (EU) 2016/679
All personal data processing within Treda is governed by the EU General Data Protection Regulation (Regulation (EU) 2016/679). We maintain Records of Processing Activities (ROPA), Data Protection Impact Assessments (DPIAs), and support Data Subject Access Requests (DSARs).
- Data Processing Agreement (DPA) available for all customers
- Standard Contractual Clauses (SCCs) for any non-EEA data transfers
- Privacy Shield successor framework compliance
- Annual DPIA reviews for high-risk processing operations
EU AI Act
Self-CompliantRegulation (EU) 2024/1689
Treda itself is a compliance tool, and we practice what we preach. Our platform is classified under the EU AI Act and we maintain full technical documentation, conformity assessments, and incident reporting for our own systems.
- Self-hosted classification and conformity assessment
- Technical documentation per Annex IV for our own AI features
- Article 14 human oversight compliance for automated decision features
- Article 62 incident reporting pipeline for our platform
ISO 27001
In ProgressISO/IEC 27001:2022
We are pursuing ISO/IEC 27001:2022 certification for our Information Security Management System (ISMS). This complements our existing security controls and provides third-party validation of our security posture.
- ISMS scope: all cloud infrastructure and development processes
- Statement of Applicability (SoA) covering all 93 controls
- Internal audits completed, external certification audit scheduled
- Integration with EU AI Act security requirements (Article 15)
AControls
Security controls & infrastructure.
Encryption
- AES-256 encryption at rest for all stored data (TLS 1.3 in transit)
- Customer-managed encryption keys (CMEK) via Google Cloud KMS
- Separate encryption keys per tenant with automatic rotation every 90 days
- End-to-end encryption for sensitive compliance audit logs
Access Control
- Role-Based Access Control (RBAC) with principle of least privilege
- SAML 2.0 / OIDC SSO integration (Okta, Azure AD, Google Workspace)
- Multi-factor authentication (MFA) enforced for all admin accounts
- Session management with configurable timeout and device tracking
Audit Logging
- Immutable audit trail for all data access and modifications
- Tamper-evident logging with cryptographic hash chains
- Full API request/response logging with PII redaction
- Audit log retention: 7 years (configurable per compliance requirement)
Infrastructure
- Hosted exclusively on EU-based data centers (Frankfurt, Dublin, Paris)
- SOC 2 Type II compliant cloud providers (AWS eu-central-1, GCP europe-west3)
- Network isolation with VPC, private subnets, and WAF protection
- Automated vulnerability scanning and penetration testing (quarterly)
Data Residency
- Zero cross-border data transfers outside EU/EEA by default
- GDPR-compliant data processing in certified EU facilities only
- Data residency verification with geographic binding for all storage
- Member state-specific data hosting available on request
Identity & Access
- SCIM 2.0 automated user provisioning and deprovisioning
- Just-in-time access with time-limited elevated privileges
- Privileged Access Management (PAM) for infrastructure access
- Quarterly access reviews with manager attestation
Data Residency Guarantee
Treda guarantees that all customer data remains within the European Economic Area (EEA) at all times. We operate exclusively from EU-based data centers:
- Primary: AWS eu-central-1 (Frankfurt, Germany)
- Secondary: GCP europe-west3 (Frankfurt, Germany)
- Disaster Recovery: AWS eu-west-1 (Dublin, Ireland)
- Backup: Azure West Europe (Netherlands)
Incident Response
Our incident response process follows the NIST Cybersecurity Framework and complies with GDPR Article 33 breach notification requirements:
- 24/7 on-call security team with 15-minute response SLA
- Automated threat detection with SIEM and behavioral analysis
- GDPR 72-hour breach notification commitment
- Customer notification within 4 hours of confirmed breach
Need a security assessment?
Request our full security whitepaper, SOC 2 readiness report, or schedule a technical deep-dive with our security engineering team.