Everything procurement, security and legal teams need: EU data residency, sub-processors, DPA, AI transparency and certification status. Visit the Trust Center.

Everything procurement, security, and legal need in one place. Sub-processors, DPA, data flows, model transparency, and the controls behind them.

Live controls, audit reports, sub-processors and real-time status at trust.tuteliq.ai

Data minimisation

Zero-retention by default. Inputs are never stored, never used to train models.

EU data residency

All AI inference runs on European infrastructure: Mistral Paris and OpenAI Whisper Vertex AI EU.

Encrypted at every layer

TLS 1.3 in transit, AES-256 at rest. Identity verification PII, incident content, and billing addresses are additionally encrypted at the application layer with AES-256-GCM keys held outside the database.

Compliance-ready

KOSA, COPPA, EU DSA, UK Online Safety Act, GDPR Art. 8, CAADCA, and the proposed EU Kids Act - built into the platform.

Compliance & certifications

We're certified or actively undergoing audit for the frameworks our customers operate under.

ISO 27001

SOC 2 Type II

GDPR

EU DSA

KOSA

COPPA

CAADCA

UK Online Safety Act

EU Kids Act

Framework statements describe how the Tuteliq platform supports each framework's requirements. They are not third-party certifications, and the EU Kids Act is a legislative proposal that does not yet create legal obligations.

Documents & policies

The artefacts your security review will ask for. All publicly accessible, no NDA required to read.

Privacy Policy

How we collect, process, and protect personal data.

Terms of Service

Commercial terms covering API and dashboard usage.

Data Processing Agreement

GDPR Article 28 contract, signable on request.

Sub-processors

Full list of vendors that may process customer data.

AI Transparency

Which models we use, where they run, and what data they see.

COPPA Compliance

How Tuteliq supports providers serving under-13 audiences.

KOSA Compliance

Coverage of the Kids Online Safety Act duty-of-care requirements.

GDPR Resources

Data subject rights, lawful basis, and Article 8 specifics.

How your data actually flows

Tuteliq is built around the principle that the safest data is the data we never store. Inputs go to our European AI providers, classification results return to you, and nothing is retained for training or analytics.

  • Supabase (Frankfurt) Holds your account, billing, and webhook metadata only. Never raw content.

Supabase (Frankfurt)

Holds your account, billing, and webhook metadata only. Never raw content.

  • Mistral (Paris) Text + multimodal classification. Zero-retention contract, EU-only.

Mistral (Paris)

Text + multimodal classification. Zero-retention contract, EU-only.

  • Vertex AI Whisper (EU) Voice transcription, processed in EU regions only.

Vertex AI Whisper (EU)

Voice transcription, processed in EU regions only.

  • Firestore (eur3) Your moderation decisions and audit logs, encrypted at rest with per-record keys.

Firestore (eur3)

Your moderation decisions and audit logs, encrypted at rest with per-record keys.

SECURITY PRACTICES

  • Single-tenant logical isolation per customer workspace
  • Row-Level Security on every database table; no cross-tenant queries possible
  • Mandatory 2FA (TOTP, AAL2) for all admin accounts
  • Brute-force lockout after 5 failed logins (60s cool-down)
  • Webhook validation: HTTPS-only, internal-IP block-list, signed payloads
  • API key rotation with one-time visibility, hashed-only storage (SHA-256)
  • Immutable audit log on all incident, decryption, and admin actions
  • Rate limits enforced at both edge and database layer

What we encrypt, and how

Every layer is encrypted at rest and in transit. The fields most likely to expose a person are additionally encrypted at the application layer, so even direct database access reveals only ciphertext.

Data

Where

Encryption

Key holder

Identity verification PII (document number, DOB, selfie ref)

Postgres (Frankfurt)

AES-256-GCM at app layer + AES-256 at rest

Tuteliq KMS

Incident content snippets and detected patterns

Billing address, company name, VAT number

API keys and plugin tokens

SHA-256 hash only (plaintext shown once at creation)

Not recoverable

Passwords

Supabase Auth

bcrypt hash

TOTP / 2FA secrets

Encrypted by Supabase Auth

Supabase

Account email, name, country, plan tier

AES-256 at rest (needed in plaintext for auth, billing, RLS)

Tuteliq + Supabase

Card numbers

Stripe (PCI-DSS Level 1)

Never stored on Tuteliq infrastructure

Stripe

Raw moderated content

Mistral Paris / Whisper EU (Vertex)

Zero-retention contracts; not persisted by us

Customer-Managed Keys (BYOK) for identity and incident records are on the roadmap for Enterprise tenants. Contact us if this is required for your procurement.

Found a vulnerability?

We take responsible disclosure seriously. Report security issues directly to our team - see our security.txt for the latest contacts and PGP key.

Need something not listed here?

SIG questionnaires, custom DPAs, regional residency questions - we answer them.

Tuteliq Trust Center

The Tuteliq Trust Center is the single source of truth for security, privacy, and compliance. We host every artefact your security review will ask for — no NDA required.

Tuteliq runs on EU-only infrastructure: Mistral (Paris) for inference, Vertex AI Whisper (EU regions) for voice transcription, Supabase (Frankfurt) for metadata, and Firestore (eur3) for moderation decisions. Customer content is never used for training.

Get Started Free · Read Documentation · View Pricing