Security & compliance

Designed for
the strictest
data rooms.

Deal data is the highest-sensitivity data your firm handles. We built undrsight with that premise from day one — per-organisation tenant isolation, encryption at rest, training opt-outs with LLM providers, EU-first hosting, and auditability you can hand to your IR team without blushing.
01

Your data, your tenant.

Each organisation lives in its own workspace. Every file is encrypted with a per-organisation key (KEK) wrapping a per-file data key (DEK), so data never crosses tenant boundaries even at the storage layer. We do not train our own models on customer documents.

For Enterprise customers, we can provision a fully dedicated tenant in the EU region of your choice, with your own key management integration (AWS KMS or customer-managed HSM) on the 2026 roadmap.

  • Encryption
    AES-256-GCM at restPer-org KEK, per-file DEK · TLS in transit
  • Key mgmt
    Env-held master key with backup procedureAWS KMS / customer-managed (BYOK) — on the roadmap
  • Tenant model
    Row-level isolation per organisationDedicated tenant available on request (Enterprise)
02

No training use by default.

Your documents, financial models, and report drafts are processed only to provide the service to your organisation. We do not train our own models on customer content, and our LLM provider configuration and contracts are designed to opt customer content out of model-training use.

Provider-side logs, temporary file references, and prompt caches are managed under provider terms, our DPA, and the deletion lifecycle described below.

  • Retention
    Provider lifecycle controlsPrompt/file handling governed by DPA + provider safeguards
  • Deletion
    One-click deletion request per dealHard-delete pipeline after the grace window
  • Portability
    Export reports as PDF, DOCX, or JSON anytimeFull deal-archive download — 2026 roadmap
03

EU-first residency.

undrsight is a Belgian company operating on European infrastructure. Core application hosting and deal-document storage are in the European Union, with international transfers limited to approved sub-processors and governed by our DPA and Standard Contractual Clauses where applicable.

For LLM inference, the inputs needed to produce the requested analysis may be sent to approved API providers outside the EEA under transfer safeguards. Enterprise customers with stricter requirements can scope dedicated regional processing controls as part of the contract.

  • Regions
    EU-hosted application + deal-document storageAdditional regional controls available on Enterprise
  • Transfers
    Limited sub-processor transfers under SCCsDetailed in the DPA and sub-processor list
  • DPA
    GDPR-compliant DPA signed with every customerSCCs attached where applicable
04

Auditable, end-to-end.

Every action in undrsight is logged: who uploaded what, when, who read which finding, who exported which report. The audit trail is immutable-append-only, exportable as CSV today — ready for your internal compliance team or external auditors.

TOTP-based multi-factor authentication can be enabled per user account today. SSO via SAML 2.0 / OIDC, SCIM provisioning, and IP allow-listing are on the 2026 roadmap for Sovereign customers — reach out if you need them on a pilot.

  • Audit log
    Immutable append-only, 7-year retentionCSV export today · SIEM streaming on the 2026 roadmap
  • Access
    User-level MFA (TOTP) + per-org session policiesSAML / OIDC / SCIM — 2026 roadmap
  • Sessions
    Configurable 2h – 168h per orgIP allow-lists — 2026 roadmap
Compliance posture

Certifications & frameworks.

We invest in certifications that our customers' compliance teams actually ask for — not vanity badges.

SOC 2

Type II audit

Working toward SOC 2 Type II. Controls being implemented now; audit window starts once the operating-effectiveness period accumulates. Report will be available under NDA.

Audit on the 2026 roadmap
ISO 27001

Information security

ISMS being built toward ISO 27001:2022 alignment. Certification timeline depends on the SOC 2 work landing first.

Certification on the 2027 roadmap
GDPR

Regulation (EU) 2016/679

Belgian entity, EU-hosted core platform, and SCC-backed international transfers for approved sub-processors. DPA available for every customer; operational GDPR records and runbooks are maintained as part of the compliance programme.

Operational programme
NIS2

Directive (EU) 2022/2555

NIS2 is tracked as part of our security roadmap. Applicability depends on customer sector, entity role, and national implementation.

Monitored
Data lifecycle

Where your documents go.

A simplified view of how a document moves through undrsight, from upload to delete request.

01 · Ingest
Upload
  • TLS 1.3 upload
  • Virus + malware scan
  • AES-256 encryption
02 · Process
Isolated workspace
  • Per-org row isolation
  • DPA-governed LLM inference
  • Provider lifecycle controls
03 · Output
Delivered & logged
  • Cited, verifiable report
  • Audit trail captured
  • One-click hard-delete
Security questions?

Talk to our security team.

We'll walk you through our architecture, share current security documentation, and answer anything your compliance team throws at us.

Book a security review