Skip to main content

Legal

Security

Last updated: 11 July 2026

Our security posture, honestly

EquiVault is built and operated in the EU by Altitudes Cloud B.V. (Netherlands). This page lists the security measures that exist today and a public roadmap of what’s planned. One rule governs it: no certification appears here before the audit that grants it is complete.

What protects your data today

EU hosting

All infrastructure runs on AWS in European regions, operated by an EU company under EU law.

Encryption

Data is encrypted in transit (TLS 1.2+) and at rest (AES-256 on AWS-managed storage).

Workspace isolation

Every workspace is isolated at the database layer with PostgreSQL row-level security — enforced by the database engine, not just application code, and exercised by automated tests in CI.

Account security

Passwords are hashed with bcrypt and never stored in plaintext. Login endpoints are rate-limited against brute force. Single sign-on (OIDC) for Professional workspaces is rolling out; SAML is on the roadmap — contact us if it’s a requirement for your firm.

Payments

Billing runs on Stripe. Card data never touches our servers.

Receipts, not trust

The AI never writes the numbers. Every figure on the canvas comes verbatim from filings and market data, and carries its source and timestamp. Any number can be audited back to the underlying document.

GDPR

We operate under the GDPR as an EU company. Analytics on this site are cookieless by default; advertising cookies fire only with explicit consent. A Data Processing Agreement (DPA) is available on request — contact legal@equivault.ai.

Compliance roadmap

  • GDPR — our operating basis today: EU company, EU hosting, DPA available.
  • SOC 2 Type II — planned, not certified. We’ll publish progress here as the audit advances; the badge comes after the audit, never before.
  • ISO 27001 — not certified and not currently planned. If that changes, it changes here first.

An earlier version of this page claimed certifications we had not earned. We removed those claims. What you read here is the honest state, kept current.

Vulnerability disclosure

If you discover a security vulnerability in EquiVault, report it to security@equivault.ai. We acknowledge reports within two business days and prioritise fixes by severity. Good-faith security research within legal bounds will never be met with legal threats.

Contact

For security enquiries, contact security@equivault.ai.

Altitudes Cloud B.V., Netherlands