How Companin protects your data: hosting infrastructure, encryption, sub-processors, certifications, and data residency.
Companin runs on cloud infrastructure located in the European Union. The platform is deployed on managed services designed for high availability, with automatic failover and daily database backups. All services communicate over private networks with no public database exposure.
At rest: Data is stored in a managed PostgreSQL database, and file uploads in object storage, both of which provide disk-level encryption at rest.
In transit: All connections use TLS 1.2 or higher. HSTS is enforced on all public endpoints.
Credentials: Passwords are hashed with PBKDF2 (SHA-256) and never stored in plain text. API keys are stored as hashed values.
We work with a limited set of vetted sub-processors. Each has been assessed for GDPR compliance and operates under appropriate data processing agreements.
Companin is GDPR-compliant as a Data Processor under EU Regulation 2016/679. We are working toward SOC 2 Type II certification. Customers can request our current security posture documentation by emailing post@companin.tech.
All customer data — including conversation logs, knowledge base content, and organization settings — is stored and processed within the European Union. We do not replicate personal data outside the EU except as required to operate AI inference (see Sub-Processors above), which is covered by Standard Contractual Clauses.
EU-regulated businesses can request a signed Data Processing Agreement. Review our full DPA online or email post@companin.tech to request a countersigned copy. Data Processing Agreement.