Trust Center · version 1.2

Information Security Overview

DeepTech sp. z o.o. · Version 1.2 — pending management approval · October 2026

Document details
FieldValue
OwnerDeepTech sp. z o.o. — CTO (system owner); approved by the Management Board
Version1.2
StatusPending management approval (Management Board of DeepTech sp. z o.o.)
EffectiveOn approval — October 2026 (supersedes v1.1, v1.0 and Draft v0.9)
ReviewEvery 12 months or after a material change
ClassificationPublic

Public summary of the security controls protecting the Audomate platform, hosted on Google Cloud in EEA regions only (europe-west1 Belgium — primary; europe-west3 Germany — disaster recovery; europe-west4 Netherlands — dual-region object storage). Detailed policies (Information Security Policy, risk management, BCP) are internal and available to clients under NDA.

1. Network security

  • TLS 1.3 on all external connections; TLS 1.2 enforced as minimum — no unencrypted channels.
  • Mutual TLS (mTLS) between internal Cloud Run services via Google Cloud Service Mesh.
  • Google Cloud Armor Web Application Firewall in front of the API gateway — OWASP Top-10 protection, adaptive DDoS mitigation; rate limiting at the API gateway (FastAPI).
  • Data layer (Cloud SQL database, Cloud Storage, Memorystore cache) on private networking (VPC with Private Service Connect) — no public IP addresses.

2. Identity and access

  • SSO via SAML 2.0 / OIDC through an EU-region identity provider (Auth0, eu.auth0.com); federation with the client's own enterprise identity provider; MFA mandatory.
  • JWT access tokens with 15-minute TTL; 7-day refresh tokens with rotation; identity-provider anomaly detection.
  • Role-based access control at application level (Auditor, Vendor Manager, Compliance Manager, IT Admin); PostgreSQL row-level security as an independent second enforcement layer — cross-tenant access is structurally impossible.
  • Secrets in Google Secret Manager (customer-managed keys) with access auditing; rotation every 90 days. Internal staff access to production follows least privilege and is logged.

3. Data protection

  • Encryption at rest: AES-256 across the database (customer-managed keys via Cloud KMS), object storage (server-side encryption) and vector indexes; key rotation every 90 days with alerts on rotation failure.
  • Automated backups and point-in-time recovery on the primary database with a 7-day retention window (Cloud SQL automated backups 7 days + PITR 7 days); object storage replicated dual-region within the EEA. RPO 1–4 h, RTO 4–8 h by plan tier; last restore test: 1 September 2026, next due by 1 March 2027 (see the Business Continuity & DR Summary).
  • Hard deletion on request: a purge pipeline removes vector, relational and object-storage records in one operation.

4. AI-layer security

  • LLM inference and embeddings through the OpenAI API with EU data residency (EU-region project, endpoint eu.api.openai.com; contracting entity OpenAI Ireland Ltd) under Zero Data Retention terms approved on the project; no client content used for training. No other cloud AI provider is used.
  • Prompt-injection detection and input sanitisation at the API gateway before any model call; per-tenant session isolation; per-tenant token budgets with utilisation alerts (protection against denial-of-wallet).

5. Logging and monitoring

  • Immutable, hash-chained audit log of every user action, AI verdict and human override.
  • Centralised monitoring (Cloud Monitoring + Cloud Logging) with error-rate, latency and LLM dashboards; alerts routed to the on-call engineer through PagerDuty; syslog (RFC 5424) / REST forwarding to the client's SIEM available.

6. Incident management

Severity-based response with on-call escalation via PagerDuty: critical incidents — tenant isolation, CTO/CEO escalation within 15 minutes, affected-client notification within 30 minutes (Enterprise) or 24 hours (Standard/Pro); personal-data breaches notified per GDPR art. 33 within 72 hours to the supervisory authority (PUODO) and within 24 hours to affected clients as controllers; personal-data aspects are coordinated by the Data Protection Coordinator (Kacper Raubo, kacper.raubo@deeptech.pl). See the Incident Response & Breach Notification Summary.

7. Certifications

Hosting layer (Google Cloud): ISO 27001, SOC 2, CSA STAR — inherited infrastructure controls. DeepTech organisation: ISO 27001 in preparation (target: Q1 2027); independent penetration test planned for Q1 2027 — vendor selection in progress. Reports will be published in the Trust Center when complete.

8. Vulnerability disclosure

We welcome reports from security researchers and clients about vulnerabilities in audomate.eu, app.audomate.eu or our APIs (coordinated vulnerability disclosure, in line with ENISA guidance on Regulation 2024/2690, Annex section 6.10).

  • Report to security@audomate.eu (mailbox live); our contact details and policy are also published in machine-readable form at audomate.eu/.well-known/security.txt (RFC 9116).
  • We acknowledge receipt within 5 business days, keep you informed about progress and tell you when the issue is fixed; vulnerabilities are triaged by the CTO using CVSS severity and remediated under the patch SLA in section 7.
  • Please act in good faith: do not access, modify or delete data that is not yours, do not disrupt the service, and give us reasonable time to fix the issue before public disclosure. We will not pursue legal action against research that respects these rules.

Document control

VersionDateAuthorApproved byChanges
0.9September 2026DeepTech (CTO / CEO)— (working draft, not adopted)Working draft published for transparency; items marked "to confirm".
1.0October 2026DeepTech (CEO / CTO)— (superseded by 1.1)Changes after the GDPR (RODO) / NIS2 audit of 7–8 October 2026: section 7 "pending" replaced by a proposed secure-development baseline (flagged for CTO confirmation); new section 9 "Vulnerability disclosure" (security@audomate.eu, security.txt); PagerDuty, Google Cloud Service Mesh, Cloud Armor, Private Service Connect and Auth0 EU specified from Annex #2; section 8 kept with date confirmation flag.
1.110 October 2026DeepTech (CEO / CTO / data protection coordinator)Management Board — pendingUpdates after Management Board decisions of 10 Oct 2026: AI layer corrected to OpenAI Ireland Ltd (OpenAI API, EU data residency, Zero Data Retention) — no other cloud AI provider used; backup window 7 days and last restore test (1 September 2026) added to section 3; security@audomate.eu confirmed live; Data Protection Coordinator named (Kacper Raubo).
1.211 October 2026DeepTech (CEO / CTO / data protection coordinator)Management Board — pendingDates confirmed by the Management Board on 11 Oct 2026: ISO 27001 certification target Q1 2027 (was H1 2027) and penetration test Q1 2027. Secure-development section removed pending CTO confirmation of current practice; sections renumbered (Certifications 7, Vulnerability disclosure 8).

Back to the Trust Center document library