Enterprise Security

Enterprise-grade security and KVKK compliance

Your data is hosted in the EU, the identity architecture is auditable, and the model core is open-source. Run KVKK-compliant marketing analytics on infrastructure you can verify.

Data Location and EU Region Hosting

  • European region, GDPR-compliant hosting
  • Hosted in the EU region — PostgreSQL, JSONB, Row Level Security
  • Backup: daily snapshot and point-in-time recovery
  • Automated data flow records under KVKK Article 9
  • Right-to-erasure completed within 48 hours via an automated flow (Platform Admin approved)

Identity Management and RLS Tenant Isolation

  • Clerk authentication — MFA supported
  • Org-scoped tenant isolation (PostgreSQL Row Level Security)
  • All org-access events recorded in an audit log
  • Cross-org access only via platform admin privilege
  • Invitation-only onboarding — self-serve signup disabled

Model Auditability — Version-Locked, Fixed Seed

  • Open-source Bayesian core (Google Meridian)
  • Fixed seed and version-locked dependency chain — the same data yields the same result
  • Posterior artifact archive for every model run
  • R-hat convergence check (≤ 1.1) reported automatically
  • Model logic and prior assumptions open to client review
→ Meridian GitHub

Compliance Roadmap

KVKK — Current

Data flow records, PII detection and erasure-right flow are active.

SOC 2 — Planning

Audit process under evaluation.

ISO 27001 — Planning

Under evaluation within the information security management system.

Incident Response

  • 4-hour notification SLO for critical security events
  • Direct communication with affected customers
  • Post-mortem publication policy

Run a technical security review

Meet with our technical team on architecture, KVKK flows and model auditability — and assess your enterprise SaaS security requirements together.

Request a Demo