Your data. Protected.

Built on defense-in-depth infrastructure in the European Union. Validated every day. No customer data stored by AI sub-processors.

How we protect your data

🔑

Strong authentication

MFA enforced for every account. Optional SSO via Google or Microsoft.

🧱

Tenant isolation

Data separation enforced at the infrastructure layer, not just application code.

🔐

Encryption everywhere

TLS 1.2+ in transit, AES-256 at rest. No unencrypted data touches disk or leaves our network.

📡

Continuous monitoring

Threat detection, immutable audit logs, and vulnerability scanning, 24/7.

🇪🇺

EU data residency

All data stored and processed in the EU. AI services run in EU regions and store nothing.

📘

Privacy by design

GDPR Article 28 DPA, documented sub-processors, and no AI training on customer data.

Defense-in-depth Architecture

A high-level view of how requests and data flow through independent layers of protection.

USER PERIMETER APPLICATION DATA Authenticated user MFA enforced Optional SSO TLS 1.2+ everywhere Web app firewall Rate limiting · Bot & DDoS Encrypted gateway HTTPS only · Private Network Identity service Per-account access scoping Application Isolated compute No direct inbound access Encrypts data before storage Public reference data Regulatory databases Read-only Your private data Per-tenant isolation Encrypted at rest AI services EU only · no data stored CONTINUOUS MONITORING Threat detection · immutable audit logging · automated vulnerability scanning · alerting & documented response
Your private data (isolated & encrypted) Public regulatory reference data AI services (EU only, no data stored) Per-account access scoping

User

  • Authenticated user
  • MFA enforced
  • Optional SSO
  • TLS 1.2+ everywhere

Perimeter

Web app firewall

  • Rate limiting
  • Bot & DDoS

Encrypted gateway

  • HTTPS only
  • Private Network

Application

Identity service

  • Per-account access scoping

Application

  • Isolated compute
  • No direct inbound access
  • Encrypts data before storage

Data

Public reference data

  • Regulatory databases
  • Read-only

Your private data

  • Per-tenant isolation
  • Encrypted at rest

AI services

  • EU only
  • No data stored

Continuous monitoring

  • Threat detection
  • Immutable audit logging
  • Automated vulnerability scanning
  • Alerting & documented response

Encrypted gateway

  • HTTPS only · private network

Compliance & Assurance

CSA CAIQ v4.1.0

Complete self-assessment against the Cloud Controls Matrix. Fully encompasses ISO 27001, extends to SOC 2 and NIST.

    CIS & FSBP, daily checks

    Automated benchmark validation runs every day. Built on AWS infrastructure certified to SOC 2 and ISO 27001.

      Vulnerability testing

      Latest CVE detection templates. Continuous container and dependency scanning.

        Resources

        Documentation, legal terms and how to reach our security team.

        Sub-processors

        The third-party services we rely on to deliver Guideways, and what they process.

        Link: View sub-processors →

        Terms of Service & DPA

        Our terms of service, including the GDPR Article 28 Data Processing Agreement.

        Link: Read terms of service →

        Contact our security team

        Security questions, vendor assessments, or to report a vulnerability. We welcome responsible disclosure.

        Email: security@guideways.ai