Designed for
the strictest
data rooms.
Your data, your tenant.
Each organisation lives in its own workspace. Every file is encrypted with a per-organisation key (KEK) wrapping a per-file data key (DEK), so data never crosses tenant boundaries even at the storage layer. We do not train our own models on customer documents.
For Enterprise customers, we can provision a fully dedicated tenant in the EU region of your choice, with your own key management integration (AWS KMS or customer-managed HSM) on the 2026 roadmap.
- EncryptionAES-256-GCM at restPer-org KEK, per-file DEK · TLS in transit
- Key mgmtEnv-held master key with backup procedureAWS KMS / customer-managed (BYOK) — on the roadmap
- Tenant modelRow-level isolation per organisationDedicated tenant available on request (Enterprise)
No training use by default.
Your documents, financial models, and report drafts are processed only to provide the service to your organisation. We do not train our own models on customer content, and our LLM provider configuration and contracts are designed to opt customer content out of model-training use.
Provider-side logs, temporary file references, and prompt caches are managed under provider terms, our DPA, and the deletion lifecycle described below.
- RetentionProvider lifecycle controlsPrompt/file handling governed by DPA + provider safeguards
- DeletionOne-click deletion request per dealHard-delete pipeline after the grace window
- PortabilityExport reports as PDF, DOCX, or JSON anytimeFull deal-archive download — 2026 roadmap
EU-first residency.
undrsight is a Belgian company operating on European infrastructure. Core application hosting and deal-document storage are in the European Union, with international transfers limited to approved sub-processors and governed by our DPA and Standard Contractual Clauses where applicable.
For LLM inference, the inputs needed to produce the requested analysis may be sent to approved API providers outside the EEA under transfer safeguards. Enterprise customers with stricter requirements can scope dedicated regional processing controls as part of the contract.
- RegionsEU-hosted application + deal-document storageAdditional regional controls available on Enterprise
- TransfersLimited sub-processor transfers under SCCsDetailed in the DPA and sub-processor list
- DPAGDPR-compliant DPA signed with every customerSCCs attached where applicable
Auditable, end-to-end.
Every action in undrsight is logged: who uploaded what, when, who read which finding, who exported which report. The audit trail is immutable-append-only, exportable as CSV today — ready for your internal compliance team or external auditors.
TOTP-based multi-factor authentication can be enabled per user account today. SSO via SAML 2.0 / OIDC, SCIM provisioning, and IP allow-listing are on the 2026 roadmap for Sovereign customers — reach out if you need them on a pilot.
- Audit logImmutable append-only, 7-year retentionCSV export today · SIEM streaming on the 2026 roadmap
- AccessUser-level MFA (TOTP) + per-org session policiesSAML / OIDC / SCIM — 2026 roadmap
- SessionsConfigurable 2h – 168h per orgIP allow-lists — 2026 roadmap
Certifications & frameworks.
We invest in certifications that our customers' compliance teams actually ask for — not vanity badges.
Type II audit
Working toward SOC 2 Type II. Controls being implemented now; audit window starts once the operating-effectiveness period accumulates. Report will be available under NDA.
Information security
ISMS being built toward ISO 27001:2022 alignment. Certification timeline depends on the SOC 2 work landing first.
Regulation (EU) 2016/679
Belgian entity, EU-hosted core platform, and SCC-backed international transfers for approved sub-processors. DPA available for every customer; operational GDPR records and runbooks are maintained as part of the compliance programme.
Directive (EU) 2022/2555
NIS2 is tracked as part of our security roadmap. Applicability depends on customer sector, entity role, and national implementation.
Where your documents go.
A simplified view of how a document moves through undrsight, from upload to delete request.
Upload
- TLS 1.3 upload
- Virus + malware scan
- AES-256 encryption
Isolated workspace
- Per-org row isolation
- DPA-governed LLM inference
- Provider lifecycle controls
Delivered & logged
- Cited, verifiable report
- Audit trail captured
- One-click hard-delete
Talk to our security team.
We'll walk you through our architecture, share current security documentation, and answer anything your compliance team throws at us.
Book a security review