Trust & Security Center
Don't take our word for it. Check ours.
Our security posture is verified automatically against the live deployment and timestamped on every run — we publish only what the collector confirms, never a hand-set status.
Continuously verified · last collector run 2 h ago
✓
All systems verified
5 of 5 controls passing
100%
Uptime 90d
100%
Core data in EU
0
Open incidents
EU data residency AES-256 · TLS 1.3 GDPR-native Hash-sealed evidence No US sub-processors for core data
Live security posture
Clickjacking protection
enforced · X-Frame-Options: DENY
Verified 2 h ago · 2026-08-07 05:00 UTC
Content Security Policy
enforced · 9 directives
Verified 2 h ago · 2026-08-07 05:00 UTC
Application liveness
healthy · db connected · 89ms round-trip
Verified 2 h ago · 2026-08-07 05:00 UTC
HTTP Strict Transport Security
enforced · max-age 730d
Verified 2 h ago · 2026-08-07 05:00 UTC
TLS certificate
valid · 29 days to renewal
Verified 2 h ago · 2026-08-07 05:00 UTC
EU data residency
Application hostingHetzner CPX32 (Nuremberg, Germany)EU
DatabasePostgreSQL on Hetzner (Nuremberg, Germany)EU
File storageHetzner Object Storage (Falkenstein, Germany)EU
AI processingMistral AI (Paris, France)EU
Rate-limit storeUpstash Redis (AWS eu-central-1, Frankfurt)EU
Error monitoringSentry EU region (Germany)EU
Product analyticsPostHog EU Cloud (Frankfurt)EU
Transactional emailResend (San Francisco, USA)SCCs
Payment processingStripe (Dublin, Ireland · PCI DSS L1)SCCs
Sign-in & analyticsGoogle (Ireland · USA)SCCs
Sign-in (Entra ID)Microsoft (Ireland · USA)SCCs
Evidence connectorGitHub (USA) — opt-inSCCs
Evidence connectorAtlassian Jira (USA) — opt-inSCCs
AI training useContractually excluded
Supervisory authorityIrish DPC
Sub-processors
ProviderPurposeLocationDPA
Stripe Payments Europe, Ltd.
Payment processing & subscription billing
Dublin, Ireland (EU) · USA (SCCs) · upd 2026-06-22
DPA →Compliance & certifications
Preparing
Cyber Resilience Act
SBOM + vuln-disclosure live; CRA obligations phasing in
Compliant
GDPR
Reg. (EU) 2016/679 · DPA, DSAR, breach process
Planned
ISO 27001
Controls foundation in progress · target 2026
Planned
ISO 42001
AI management system — our differentiator
Request the full security report
Penetration-test summaries, the SOC-style controls matrix, and our detailed architecture review are shared under NDA. Enter your work email and accept the non-disclosure terms to receive the full report.
Policies & documents
SBOM →
CRA-compliant dependency transparency
Vulnerability Disclosure →
Responsible disclosure policy & process
Sub-processors →
Every third party that touches your data
DPA →
GDPR-compliant data processing agreement
AI Transparency →
How Aria uses AI, and your controls
Data Request →
Exercise your GDPR data-subject rights
Terms of Service →
Platform usage terms & liability
Acceptable Use →
Permitted use of the platform
Enterprise security inquiries
For security questionnaires or custom DPA negotiations, contact security@veritome.eu