Skip to content
Trust

Security & compliance

Stedral runs your business and holds your company data, so how we protect it matters. Here's the honest picture — what we do today, and what we're still building.

EU data residency

Your company data is stored at rest in the European Union (Hetzner, Germany). Where a sub-processor outside the EU is used, transfers are governed by Standard Contractual Clauses.

Encryption

Data is encrypted in transit (TLS) and connected-account credentials are encrypted at rest with AES-256-GCM. Card data never touches our servers — payments run through Stripe (PCI-DSS).

Tenant isolation

Every customer's data is isolated at the database layer with Postgres row-level security, so one tenant can never read or write another's records.

Your data rights

Export or erase your data at any time. A Data Processing Agreement (DPA) is available, our sub-processors are published, and GDPR access/rectification/erasure rights are supported.

Human-in-the-loop AI

Your agents propose; you decide. An invoice, a reply, a deal moved, a post — all of it lands in your approval queue and does nothing until you approve it. One action can reach someone directly: a live-chat reply to a visitor on your site. That one obeys the standing permissions you set per agent — draft-and-wait, a daily cap, an active window, or specific sessions only. AI-generated content is labelled (EU AI Act Art. 50).

Your agents don't take orders from your inbox

Agents read text other people wrote — a support email, a customer's name, a note on a deal. Anything a tool hands an agent arrives inside a boundary the text itself cannot break out of, and agents are instructed to act on what it means, never on what it tells them to do; anything issuing orders gets flagged to you instead. No filter is a guarantee, which is why this sits behind the approval queue rather than in front of it.

Built to SOC 2 criteria

Our controls map to the SOC 2 Type II trust criteria — encryption, tenant isolation, an append-only audit trail, role-based access, and monitored backups are all in place today. The independent third-party audit isn't complete yet, so we don't claim the certification — we'll engage an auditor as we move upmarket. Happy to walk a prospect through our controls on request.

Security & Compliance — Stedral by Digitalix Hub