TRUST & SECURITY

TRUST BUILT FOR EU OPERATIONS

Security and data sovereignty are not features we add. They are the foundation every Altovar product is built on.

  • EU jurisdiction only
  • Auditable by default
  • No third-country data
  • Open standards
100% EU-HOSTED
GDPR BY DESIGN
24h INCIDENT RESPONSE
EU JURISDICTION
OPERATING RULES

The rules we operate by.

EU jurisdiction only

Customer data stays in European data centres and under EU law, without hidden routing through third countries.

No outsourced trust layer

No US cloud, CDN, or analytics dependency between your users, your logs, and your compliance obligations.

Controls you can verify

Audit trails, access controls, encryption, and compliance status remain visible when review becomes procurement work.

Foundation

Three commitments that shape every product decision.

01
DATA IN EU

Every byte of customer data is stored and processed in European data centres, under EU law only.

02
ZERO THIRD-COUNTRY EXPOSURE

We do not rely on US cloud providers, CDNs, or analytics layers that can reintroduce foreign surveillance risk.

03
AUDITABLE BY DEFAULT

Open standards, published architecture, and immutable logs mean you can verify what happens to your data.

Regulation

Status is explicit, not implied.

GDPR

Personal data is processed under GDPR with data minimisation, access rights, erasure handling, and breach procedures in place.

COMPLIANT
NIS2

Incident response, supply-chain security, and reporting procedures are being formalised across the stack.

IN PROGRESS
eIDAS

Auris supports eIDAS-aligned identity flows, and Sigil is designed around European signature requirements.

COMPLIANT
EU AI ACT

Telesis is being built with human oversight, explainability, and clear prohibited-use boundaries from the start.

MONITORING
Controls

Security controls that stay visible when procurement starts asking questions.

01

END-TO-END ENCRYPTION

Data in transit and at rest is encrypted with modern standards. Echo applies Signal Protocol for message E2EE.

02

MULTI-FACTOR AUTHENTICATION

TOTP, WebAuthn, hardware keys, and SMS OTP are available through Auris, with tenant-level policy enforcement.

03

ROLE-BASED ACCESS CONTROL

Fine-grained RBAC and Zanzibar-style FGA support complex permission models across products.

04

FULL AUDIT LOGS

Administrative actions, API calls, and user events are logged for compliance review and forensic work.

05

OPEN SOURCE COMPONENTS

Key security layers are auditable, and we publish architecture details instead of hiding them behind marketing claims.

06

EU DATA CENTRES ONLY

Data is stored and processed in EU-based facilities only. No third-country transfers, no US Cloud Act exposure.

SECURITY

YOUR DATA STAYSIN EUROPE.

No exceptions, no workarounds, no US Cloud Act exposure. We built the infrastructure we wanted to buy ourselves.

Learn more →