Euryan Euryan
Legal · Trust

Security Overview

Version 1.0  ·  Last updated 24 July 2026

This Security Overview describes the technical and organisational measures Euryan applies to protect customer data. It forms part of the Data Processing Addendum as the measures referred to in clause 4.2, and populates Annex II of the Standard Contractual Clauses where those apply.

The platform is pre-production and no customer data is processed today. The measures below describe the production configuration that will be in place before the first customer deployment, and before any customer data exists.

Hosting and data residency

Primary application hosting, database operations and backups run in the European Union, in Amazon Web Services’ Frankfurt region (eu-central-1). Per-tenant hosting in another region is available by agreement.

Tenant isolation

Tenant isolation is enforced in a single mandatory data-access layer through which all graph access passes, not in per-endpoint application code. Every node carries a tenant identifier stamped server side, and relationships are tenant scoped through their endpoints. The tenant identifier is constructed server side, is never accepted from client input, and cannot be set or overridden by model output.

AI processing

Generative inference runs on Amazon Bedrock within our EU region. Bedrock does not retain prompts or completions, and the underlying model providers have no access to them. AI agents execute only against predefined, parameterised schemas with no free-form graph traversal: the query is fixed and model output can only fill typed parameters. Euryan does not use customer data to train, tune or develop any machine-learning model. Customer content carried in workflow payloads is encrypted by our workers before transmission to the workflow service, so that the service holds only ciphertext of customer data together with generic workflow metadata.

Encryption

Data is encrypted in transit using TLS 1.3, with TLS 1.2 as the minimum. Data is encrypted at rest using AES-256. The database is protected by managed encryption keys; object storage and backups are encrypted with keys held in our own key-management service.

Network

All connections are TLS-enforced with certificate validation. Application infrastructure runs in private subnets with security-group controls, and database access is credential-gated. Private database networking is available for customers who require it.

Access control

Access to production systems is restricted to authorised personnel on a need-to-know basis, each bound by a duty of confidentiality. Access rights are reviewed quarterly. On role change or departure, access is revoked within 24 hours against a checklist covering compute, database, source control, workflow orchestration and authentication. Authentication to the platform is provided by AWS Cognito, with SAML federation for enterprise single sign-on.

Logging and monitoring

Authentication, administrative-action and data-access logs are written to an append-only store and retained for twelve months. Monitoring runs on Amazon CloudWatch within our region. No third-party error-reporting tool that captures customer payloads is in use.

Backups and recovery

The database is protected by daily automated snapshots with seven-day retention. Restores are tested quarterly and the result recorded. On termination, customer personal data is deleted or returned in line with clause 9 of the DPA, from live systems within 30 days and from backups within 60.

Change management

All changes land through pull requests with automated checks, including dependency scanning. Secret scanning and push protection are enabled on the source repository. Development, staging and production environments are separated.

Incident response

Euryan maintains a documented incident-response procedure covering detection, assessment, containment, notification and post-incident review, aligned with clause 7 of the DPA and Articles 33 and 34 of the UK and EU GDPR. It is available on request.

Vulnerability reporting

Report a security concern to security@euryan.com. This inbox is monitored and is the address referenced in our security.txt.

Subprocessors

The third parties Euryan engages to process customer data are listed on the Subprocessor List, with at least 30 days notice before any change.

Certifications

Euryan is working towards certification in the sequence ISO 9001, SOC 2 Type II, ISO/IEC 27001 and TISAX. These are in progress and not yet held. We describe our current posture accurately rather than claim certifications we do not hold.

Questions

Contact security@euryan.com for security matters, or info@euryan.com otherwise. The Data Processing Addendum and Subprocessor List answer most standard supplier-assessment items.