Custodea
Security & data sovereignty

Trust, on the record.

Custodea exists because European businesses shouldn't have to choose between modern data tooling and legal certainty. Below is an honest, current account of how we run the platform — what's true today, what's in flight, and what we won't do.

 Falkenstein    Helsinki  Custodea B.V.  GDPR compliant
GDPR
Compliant
ISO 27001
Planned · Q4 2026
SOC 2 Type II
Planned · 2027
§01

Data residency

All tenant data — connector credentials, raw extracts, the warehouse, backups, and audit logs — lives in EU data centres: primary capacity in Falkenstein, Germany and encrypted backups in Helsinki, Finland. No tenant byte ever leaves EU territory or transits a US-headquartered cloud.

  • Primary: Falkenstein, Germany (Hetzner)
  • Backup: Helsinki, Finland (Hetzner)
  • No AWS · no Azure · no Google Cloud
  • Operated by Custodea B.V., Amsterdam
§02

Encryption

Data is encrypted at rest with LUKS-managed AES-256 on each storage volume and encrypted in transit with TLS 1.3. Connector credentials are wrapped a second time with a KMS-style envelope; the unwrapping key never leaves the warehouse cluster.

  • AES-256 at rest, TLS 1.3 in transit
  • Per-tenant credential envelope keys
  • Database backups encrypted with separate keys
§03

Access control

You hold the keys. Credentials for each tool — your BI dashboard, dbt, your auditor's read-only access — are minted in Settings and revoked the same way.

  • Per-tool credentials you mint and revoke
§04

What we won't do

We don't sell or share your data. We don't train models on it. We won't add a US sub-processor to make a feature ship faster. The product roadmap exists downstream of these constraints, not the other way around.

§05

Compliance & audits

We're GDPR-compliant by default and sign a DPA with every customer at sign-up. ISO/IEC 27001 is planned for Q4 2026 and SOC 2 Type II is planned for 2027. The internal control framework is in place; what's still happening is the third-party audit.

  • GDPR — compliant; DPA signed at sign-up
  • ISO/IEC 27001 — planned for Q4 2026
  • SOC 2 Type II — planned 2027
§06

Incident response

We aim for a 1-hour internal acknowledgement and a 24-hour customer notification on any confirmed security incident affecting tenant data.