EU data residency
Stored and processed in the EU — enforced, not configured.
Security & compliance
Granite holds sensitive lease, financial, and contract data for enterprise tenants. The platform is built to an enterprise correctness bar from day one — EU-resident, encrypted, auditable, and GDPR-first.
Stored and processed in the EU — enforced, not configured.
AES-256 at rest, TLS 1.3 in transit, customer-managed keys.
Federated SSO, MFA, and least-privilege roles.
Every change and access recorded to an immutable log.
Processed in the EU; never used to train models.
Isolated at the database layer, beneath the application.
Data residency
EU data residency is a hard requirement, enforced by infrastructure — not a per-customer configuration option.
Identity & access
Access is federated to your own identity provider and enforced top to bottom — from sign-in to the database row.
Data protection & GDPR
Granite processes your data as a processor under a Data Processing Agreement entered into with every customer; you remain the controller.
The website's own privacy practices are described in our Privacy Policy and DPA & sub-processors page; the product platform is covered by the customer DPA.
Responsible AI
Granite's AI works on your own data inside a closed system. It is built to the same correctness bar as the system of record.
Reliability & continuity
The platform runs with regional high availability and can be rebuilt from version-controlled infrastructure.
What we don't do
GDPR
By designEU data residency, lawful-basis and DPA tracking, and data-subject rights are built in — GDPR is foundational, not a future milestone.
SOC 2 Type II
In progressControls and evidence are being implemented to the SOC 2 framework ahead of a Type II audit; reports will be available to enterprise customers under NDA once the programme is operational.
ISO 27001
AlignedOur controls are aligned to ISO 27001, which overlaps substantially with SOC 2; formal certification will follow as customers require it.
Access control
By designTenant data is isolated at the database layer with row-level security, layered with role-based, least-privilege access controls.
Independent testing
PlannedIndependent penetration testing and annual third-party security audits run as part of the SOC 2 programme.
For procurement
For enterprise procurement, we provide our Data Processing Agreement, the current product sub-processor list, completed security questionnaires, and audit reports under NDA.
Reach sales@granitestrata.com for procurement, or security@granitestrata.com for security questions.