Security Overview
This Security Overview describes the technical and organisational measures Euryan applies to protect customer data. It forms part of the Data Processing Addendum as the measures referred to in clause 4.2, and populates Annex II of the Standard Contractual Clauses where those apply.
Hosting and data residency
Primary application hosting, database operations and backups run in the European Union, in Amazon Web Services’ Frankfurt region (eu-central-1). Per-tenant hosting in another region is available by agreement.
Tenant isolation
Tenant isolation is enforced in a single mandatory data-access layer through which all graph access passes, not in per-endpoint application code. Every node carries a tenant identifier stamped server side, and relationships are tenant scoped through their endpoints. The tenant identifier is constructed server side, is never accepted from client input, and cannot be set or overridden by model output.
AI processing
Generative inference runs on Amazon Bedrock within our EU region. Bedrock does not retain prompts or completions, and the underlying model providers have no access to them. AI agents execute only against predefined, parameterised schemas with no free-form graph traversal: the query is fixed and model output can only fill typed parameters. Euryan does not use customer data to train, tune or develop any machine-learning model. Customer content carried in workflow payloads is encrypted by our workers before transmission to the workflow service, so that the service holds only ciphertext of customer data together with generic workflow metadata.
Encryption
Data is encrypted in transit using TLS 1.3, with TLS 1.2 as the minimum. Data is encrypted at rest using AES-256. The database is protected by managed encryption keys; object storage and backups are encrypted with keys held in our own key-management service.
Network
All connections are TLS-enforced with certificate validation. Application infrastructure runs in private subnets with security-group controls, and database access is credential-gated. Private database networking is available for customers who require it.
Access control
Access to production systems is restricted to authorised personnel on a need-to-know basis, each bound by a duty of confidentiality. Access rights are reviewed quarterly. On role change or departure, access is revoked within 24 hours against a checklist covering compute, database, source control, workflow orchestration and authentication. Authentication to the platform is provided by AWS Cognito, with SAML federation for enterprise single sign-on.
Logging and monitoring
Authentication, administrative-action and data-access logs are written to an append-only store and retained for twelve months. Monitoring runs on Amazon CloudWatch within our region. No third-party error-reporting tool that captures customer payloads is in use.
Backups and recovery
The database is protected by daily automated snapshots with seven-day retention. Restores are tested quarterly and the result recorded. On termination, customer personal data is deleted or returned in line with clause 9 of the DPA, from live systems within 30 days and from backups within 60.
Change management
All changes land through pull requests with automated checks, including dependency scanning. Secret scanning and push protection are enabled on the source repository. Development, staging and production environments are separated.
Incident response
Euryan maintains a documented incident-response procedure covering detection, assessment, containment, notification and post-incident review, aligned with clause 7 of the DPA and Articles 33 and 34 of the UK and EU GDPR. It is available on request.
Vulnerability reporting
Report a security concern to security@euryan.com. This inbox is monitored and is the address referenced in our security.txt.
Subprocessors
The third parties Euryan engages to process customer data are listed on the Subprocessor List, with at least 30 days notice before any change.
Certifications
Euryan is working towards certification in the sequence ISO 9001, SOC 2 Type II, ISO/IEC 27001 and TISAX. These are in progress and not yet held. We describe our current posture accurately rather than claim certifications we do not hold.
Questions
Contact security@euryan.com for security matters, or info@euryan.com otherwise. The Data Processing Addendum and Subprocessor List answer most standard supplier-assessment items.