100% EU Hosted & GDPR Compliant

Trust by design.

Every decision starts with: is this safe? Here's what that means.

EU-hosted infrastructure

All data processed and stored in the EU. No transatlantic transfers.

Encryption in transit & at rest

TLS 1.2/1.3 in transit. AES-256 at rest. Credentials encrypted with per-tenant keys.

Tenant isolation

Dedicated database per customer. Connection-layer isolation. Single-tenant deployments on Enterprise.

GDPR compliant

GDPR compliant. DPA on request. Access, correction, deletion, portability supported.

SOC 2 roadmap

SOC 2 Type II program in place. Audit on roadmap for 2026. Docs on request.

Your data is never sold

We never sell your data. We never train AI on it. Deleted within 30 days of cancellation.

Architecture at a glance

Infrastructure

  • Scaleway Kapsule (managed Kubernetes), EU region
  • Supabase Postgres (EU region) for tenant data
  • Airbyte for ingestion (self-hosted on EU infra)
  • Apache Superset for dashboarding

Operational controls

  • Infrastructure as code (Terraform + GitOps)
  • All changes reviewed and audited
  • Automated daily backups, 30-day retention
  • 24/7 alerting on anomalies and failures

Reviewing for procurement? Read the detailed security overview →

Security FAQ

Where is my data physically stored?
All data is stored in EU-based data centres. No data is replicated outside the EU.
Can I get a signed DPA?
Yes. Email start@data-pillar.com.
Who has access to my data?
Restricted to a small ops team. Every access is logged. No customer data in dev or staging.
What happens if I cancel?
You have a 30-day grace period to export all your data. After that, we delete it from production systems within 30 days. Backups are purged within 90 days.
Do you support SSO?
Yes, on Scale. SAML 2.0 and OIDC.
Can I restrict which data goes to Pillar?
Yes. Field-level selection on every connector. Exclude PII at the source.

Want more detail?

Our security documentation, DPA, and architecture overview are available on request.