Everything procurement, security, and legal need in one place. Sub-processors, DPA, data flows, model transparency, and the controls behind them.
Live controls, audit reports, sub-processors and real-time status at trust.tuteliq.ai
Data minimisation
Zero-retention by default. Inputs are never stored, never used to train models.
EU data residency
All AI inference runs on European infrastructure: Mistral Paris and OpenAI Whisper Vertex AI EU.
Encrypted at every layer
TLS 1.3 in transit, AES-256 at rest. Identity verification PII, incident content, and billing addresses are additionally encrypted at the application layer with AES-256-GCM keys held outside the database.
Compliance-ready
KOSA, COPPA, EU DSA, UK Online Safety Act, GDPR Art. 8, CAADCA, and the proposed EU Kids Act - built into the platform.
Compliance & certifications
We're certified or actively undergoing audit for the frameworks our customers operate under.
ISO 27001
SOC 2 Type II
GDPR
EU DSA
KOSA
COPPA
CAADCA
UK Online Safety Act
EU Kids Act
Framework statements describe how the Tuteliq platform supports each framework's requirements. They are not third-party certifications, and the EU Kids Act is a legislative proposal that does not yet create legal obligations.
Documents & policies
The artefacts your security review will ask for. All publicly accessible, no NDA required to read.
Privacy Policy
How we collect, process, and protect personal data.
Terms of Service
Commercial terms covering API and dashboard usage.
Data Processing Agreement
GDPR Article 28 contract, signable on request.
Sub-processors
Full list of vendors that may process customer data.
AI Transparency
Which models we use, where they run, and what data they see.
COPPA Compliance
How Tuteliq supports providers serving under-13 audiences.
KOSA Compliance
Coverage of the Kids Online Safety Act duty-of-care requirements.
GDPR Resources
Data subject rights, lawful basis, and Article 8 specifics.
How your data actually flows
Tuteliq is built around the principle that the safest data is the data we never store. Inputs go to our European AI providers, classification results return to you, and nothing is retained for training or analytics.
- Supabase (Frankfurt) Holds your account, billing, and webhook metadata only. Never raw content.
Supabase (Frankfurt)
Holds your account, billing, and webhook metadata only. Never raw content.
- Mistral (Paris) Text + multimodal classification. Zero-retention contract, EU-only.
Mistral (Paris)
Text + multimodal classification. Zero-retention contract, EU-only.
- Vertex AI Whisper (EU) Voice transcription, processed in EU regions only.
Vertex AI Whisper (EU)
Voice transcription, processed in EU regions only.
- Firestore (eur3) Your moderation decisions and audit logs, encrypted at rest with per-record keys.
Firestore (eur3)
Your moderation decisions and audit logs, encrypted at rest with per-record keys.
SECURITY PRACTICES
- Single-tenant logical isolation per customer workspace
- Row-Level Security on every database table; no cross-tenant queries possible
- Mandatory 2FA (TOTP, AAL2) for all admin accounts
- Brute-force lockout after 5 failed logins (60s cool-down)
- Webhook validation: HTTPS-only, internal-IP block-list, signed payloads
- API key rotation with one-time visibility, hashed-only storage (SHA-256)
- Immutable audit log on all incident, decryption, and admin actions
- Rate limits enforced at both edge and database layer
What we encrypt, and how
Every layer is encrypted at rest and in transit. The fields most likely to expose a person are additionally encrypted at the application layer, so even direct database access reveals only ciphertext.
Data
Where
Encryption
Key holder
Identity verification PII (document number, DOB, selfie ref)
Postgres (Frankfurt)
AES-256-GCM at app layer + AES-256 at rest
Tuteliq KMS
Incident content snippets and detected patterns
Billing address, company name, VAT number
API keys and plugin tokens
SHA-256 hash only (plaintext shown once at creation)
Not recoverable
Passwords
Supabase Auth
bcrypt hash
TOTP / 2FA secrets
Encrypted by Supabase Auth
Supabase
Account email, name, country, plan tier
AES-256 at rest (needed in plaintext for auth, billing, RLS)
Tuteliq + Supabase
Card numbers
Stripe (PCI-DSS Level 1)
Never stored on Tuteliq infrastructure
Stripe
Raw moderated content
Mistral Paris / Whisper EU (Vertex)
Zero-retention contracts; not persisted by us
Customer-Managed Keys (BYOK) for identity and incident records are on the roadmap for Enterprise tenants. Contact us if this is required for your procurement.
Found a vulnerability?
We take responsible disclosure seriously. Report security issues directly to our team - see our security.txt for the latest contacts and PGP key.
Need something not listed here?
SIG questionnaires, custom DPAs, regional residency questions - we answer them.