Skip to main content
Security & Privacy

Your team's data, treated like ours.

Encryption in the right places, EU data hosting in Frankfurt, sign-in with a magic link or passkey plus 2FA, and a security contact who actually replies. Plain-English answers below — including what we haven't built yet.

SOC 2 Type II
Not certified yet
On our roadmap
GDPR
Built for EU data subjects
In progress
ISO 27001
Not certified yet
On our roadmap
DPA
Signed by email
Available

Data protection

Modern, boring cryptography in the right places. No clever schemes — just the things that auditors and your CISO expect.

Encryption at rest

Files in Cloudflare R2 are encrypted at rest (AES-256). Two-factor secrets are encrypted in the app with AES-256-GCM. Passwords are hashed with bcrypt.

Encryption in transit

TLS on every connection, with HSTS.

Daily backups

Daily database backups, kept in Frankfurt and rotated out within 90 days.

Audit log

Role changes, data exports and other admin actions go to an audit log kept 30 days on Free and 365 days on Pro. Owners and company admins can download up to 10,000 rows per export as CSV.

Identity & access

RBAC scoped per team today. SSO and SCIM are on our roadmap for teams that need them.

Roles that match your org

Owner / Admin / Lead / Member with per-team scope. A team lead in Helsinki can't see what Berlin is up to unless you say so.

SAML SSO + SCIM (roadmap)

Planned: wire up Okta, Google Workspace, Microsoft Entra ID, or any SAML-compliant IdP, with SCIM 2.0 to auto-deactivate seats when someone leaves your IdP. Not available yet — we'll announce it when it ships.

Two-factor authentication and passkeys

App-based TOTP 2FA with recovery codes is built in, and passkeys (YubiKey, Touch ID) are available for sign-in. Workspace-wide MFA enforcement is on our roadmap.

Sessions you can see

Every active session shows up in your account — device, IP address, last activity. One-click sign-out remotely.

Privacy

You own your team's data. We hold it under a clear DPA, in the EU, and we delete it when you say so.

Standard DPA

A standard EU-style Data Processing Agreement, published at /dpa — pre-filled and signed over email; we return a counter-signed copy. Signing it inside the app is not available yet.

EU data residency

Database and backups in Frankfurt, files in Western Europe — all inside the EU. Some processing runs in the US — the web app on Vercel, the AI provider, Stripe and Expo push — under SCCs.

Delete means delete

Deleting your account erases your personal data right away; it leaves backups within 90 days. Deleting asks for your password first — or a one-time emailed link, for accounts that never had one.

No selling, no ads, no training

Your data is never sold and never used to train models, and it's shared only with the sub-processors we list publicly — infrastructure (OVHcloud, Cloudflare, Vercel, Stripe) plus a handful of operational providers.

Where your data lives.

Your workspace data is stored in the EU today — the database in Frankfurt, files in Western Europe; the web app is served through Vercel. More regions are on the roadmap — we won't move your data without telling you.

🇩🇪EU — FrankfurtFRA
🇺🇸US — VirginiaIAD
🇸🇬APAC — SingaporeSIN
🇦🇺Australia — SydneySYD

Found a vulnerability?

We aim to reply within 2 business days and credit researchers who report responsibly. No legal sabre-rattling — just a respectful process.

Email security@altorbit.app

Frequently asked, by your CISO.