Skip to main content
HomeTrustSecurity & Compliance
Trust · for architects & security

Production-grade. ISO 27001-aligned. EU-sovereign by default.

The technical and data-handling evidence your architecture and security review needs — verifiable, documentable, and built in from layer one.

Certifications & standards

Evidence, not assurances.

Verifiable, documentable security posture — every claim below is backed by an artifact your team can file.

Certified

ISO 27001

Information-security management certified and audited — controls mapped to Annex A, evidenced on request.

By design

GDPR-native

Privacy-by-design and by-default. Lawful-basis mapping, DPIA support, data-subject workflows built in.

Aligned

SOC 2-aligned controls

Security, availability and confidentiality controls aligned to SOC 2 trust criteria.

Tested

Independent pen-testing

Annual third-party penetration testing and continuous dependency scanning across the stack.

Data residency

Your data stays under European jurisdiction.

Production data is EU-resident by default and outside the reach of the US CLOUD Act. For the highest-trust workloads we deploy inside your own perimeter.

Primary hosting · Sofia, BG (EU)EU-only data residency by defaultOutside US CLOUD-Act reach for production dataCustomer-perimeter / air-gapped option
Data-flow transparency

No black boxes. No silent hops.

You can see exactly where data goes, why, and under what control — the answer to the opaque-AI-data-flow fear.

No opaque hops

Governed data contracts

Every data movement is an explicit, documented contract. No silent multi-provider relays, no shadow copies. Your DPO can read the full map.

Provable

End-to-end lineage

Every model decision logs its inputs, version and policy gate — auditor-grade lineage you can replay, not a black box.

Encrypted

In transit & at rest

TLS 1.3 in transit, AES-256 at rest, customer-managed keys (BYOK/HYOK) where required.

Scoped

Least-privilege access

Identity inherits from your IdP. Access is role-scoped, time-boxed and fully audited — no standing admin.

Security by design

Four layers, governed end to end.

Security is architected in from layer one — not bolted on after the demo.

Layer 01

Identity & access

SSO via your IdP, SCIM provisioning, MFA, least-privilege RBAC, full access audit trail.

Layer 02

Network & perimeter

Private networking, segmented VPCs, WAF, secrets management, zero public model endpoints.

Layer 03

Data & governance

Classification, lineage, retention, DLP, and an AI risk register aligned to the EU AI Act tiers.

Layer 04

Model & ops

Eval gates, guardrails, prompt/version control, rollback, and human-in-the-loop policy where it matters.

Sub-processors

A register your DPIA can cite.

Transparent, current and minimal. EU-resident by default; the full list is available under NDA.

Sub-processorPurposeRegionSafeguard
Microsoft Azure (EU)Primary cloud & computeEU (West/North Europe)EU data boundary · SCCs
Databricks (EU)Data & ML platformEUEU residency · DPA
Self-hosted modelsInference (sovereign)EU / customer perimeterNo external transfer
Full, current register provided under NDA on request · dpo@celthrac.com
Let's build

Defensible.By design.

Bring your security questionnaire. We answer with architecture and artifacts, not adjectives.