Security & trust

We protect your data the way you protect your clients’.

We sell compliance software, so our own posture has to survive the same scrutiny. Here is exactly how Custodia is run.

ResidencyEU infrastructureHosted on AWS Dublin (eu-west-1). No data leaves the EEA, including for support access.
EncryptionEncrypted throughoutAES-256 at rest, TLS 1.3 in transit, with keys managed separately from the data.
AccessAccess controlRow-level security, role-based permissions scoped per entity, and MFA on every account.
AssuranceIndependent testingAnnual third-party penetration testing. Findings are remediated and retested before closure.
IsolationTenant isolationMulti-tenant with database-level isolation, enforced per organisation on every query.
StandardsISO 27001-alignedControls mapped to ISO 27001. SOC 2 Type II is in preparation, not yet certified.

Our own GDPR position

We keep the records we ask you to keep. Custodia maintains its own Article 30 register, assesses its own vendors, and applies its own retention schedule.

An Article 28 data processing agreement is available to every customer.
Sub-processors are assessed before onboarding and tracked thereafter.
A named data protection officer is accountable for the programme.

Sub-processors

Every third party that processes data on our behalf is listed publicly, with what it processes and where it is located. We notify customers before the list changes.

View the sub-processor list

Security enquiries

For a security questionnaire, a copy of the DPA, or to report a vulnerability, write to the security team directly. We acknowledge reports within one working day.

Email the security team
security@trycustodia.online