logo-full-gradient-black
Security & Compliance

Security Management & Data Protection

Eusate handles your customers' conversations. We treat that responsibility seriously, and we'd rather tell you exactly how our systems work than hide behind generic assurances. Here's where your data lives and how we protect it.

security illustration

hosting

EU only

Madrid + AWS eu-west-1

encryption

TLS 1.2/1.3

SSE-S3 at rest

authentication

Password-less

One-time email codes

incidents

72 hours

Customer notification

Data residency

Where your data is hosted

Both our application and our backups sit entirely within the European Union. Your data does not leave the EU in the course of normal platform operation. For customers evaluating data residency requirements, including fintech and other regulated businesses, this means your conversation data is processed and stored under EU jurisdiction by default, not routed through infrastructure outside it.

data recidency illustration

Dedicated infrastructure

Madrid, Spain

The Eusate application runs on dedicated infrastructure in Madrid — not shared multi-tenant hosting outside the EU.

Object storage & backups

AWS eu-west-1, Ireland

Files, database backups, and logs live in Amazon S3 in the Ireland region, encrypted server-side by default.

Encryption

Encrypted in transit. Encrypted at rest.

Every connection to Eusate is encrypted, and every object we write to storage is encrypted before it touches disk.

In transit

Madrid, Spain

TLS 1.2 and 1.3 only. Older, weaker protocols are refused outright.

HSTS enabled. Browsers are instructed never to attempt an unencrypted connection to us in the first place.

Encrypted WebSockets. Real-time features run over wss.

Object storage & backups

AWS eu-west-1, Ireland

SSE-S3 by default. Files, database backups, and logs are encrypted before they touch disk.

Private primary database. It runs on dedicated infrastructure that is not reachable from the public internet.

Application-layer encryption for secrets. Sensitive credentials are encrypted before they are written to the database.

Access

Credential and access management

The safest secret is the one we never hold. What we do hold is encrypted, injected at deploy time, and audited.

data recidency illustration

Encrypted secrets manager

Platform secrets and third-party API keys are injected into the runtime only at deployment. Never committed to source control, never stored in the application database.

Passwordless sign-in

Signing in uses a one-time code sent to your verified email. There is no password to be reused, phished, leaked, or stolen from us — because we never hold one.

Role-based admin audit trail

Every administrative action is recorded with the actor, the change made, the previous and new values, and the originating IP address.

Regulatory posture

Where we stand, in plain terms

We know regulatory posture is often the deciding factor for fintech and other regulated businesses. Here is exactly what is in place and what is still on the roadmap.

GDPR

Aligned infrastructure

Because our application and backups are hosted entirely within the EU (Madrid and AWS eu-west-1), Eusate's infrastructure is built on a foundation aligned with GDPR's data residency expectations. At this stage, Eusate does not yet offer a standalone Data Processing Agreement (DPA). Data processing terms are currently covered through our Privacy Policy and Terms & Conditions, which customers accept when signing up.

NDPR

In progress

Eusate is built with the core principles of the Nigeria Data Protection Regulation in mind, and formal registration is in progress as we scale our compliance program. A dedicated DPA, formal legal basis documentation, and an EU representative designation are on our compliance roadmap as we scale to serve larger regulated customers.

Specific requirements not addressed here? Contact us at info@eusate.com and we'll work through them with you.