Data Location and EU Region Hosting
- European region, GDPR-compliant hosting
- Hosted in the EU region — PostgreSQL, JSONB, Row Level Security
- Backup: daily snapshot and point-in-time recovery
- Automated data flow records under KVKK Article 9
- Right-to-erasure completed within 48 hours via an automated flow (Platform Admin approved)
Identity Management and RLS Tenant Isolation
- Clerk authentication — MFA supported
- Org-scoped tenant isolation (PostgreSQL Row Level Security)
- All org-access events recorded in an audit log
- Cross-org access only via platform admin privilege
- Invitation-only onboarding — self-serve signup disabled
Model Auditability — Version-Locked, Fixed Seed
- Open-source Bayesian core (Google Meridian)
- Fixed seed and version-locked dependency chain — the same data yields the same result
- Posterior artifact archive for every model run
- R-hat convergence check (≤ 1.1) reported automatically
- Model logic and prior assumptions open to client review
Compliance Roadmap
KVKK — Current
Data flow records, PII detection and erasure-right flow are active.
SOC 2 — Planning
Audit process under evaluation.
ISO 27001 — Planning
Under evaluation within the information security management system.
Incident Response
- 4-hour notification SLO for critical security events
- Direct communication with affected customers
- Post-mortem publication policy
Run a technical security review
Meet with our technical team on architecture, KVKK flows and model auditability — and assess your enterprise SaaS security requirements together.
Request a Demo