Trust Center
Answers for your security review
Every control, data location, and sub-processor Drall relies on — documented in one place, with what we have not built yet stated just as plainly.
Download the DPA & TOMsLast updated: August 2026
Controls at a glance
| TLS 1.2+ in transit, AES-256 at rest | Live |
| Two-factor authentication (TOTP), enforceable firm-wide | Live |
| SSO — SAML 2.0 (set up together with our team) | Live |
| Tenant isolation — Postgres row-level security on every query | Live |
| Per-project "Isolate" & "Confidential" toggles | Live |
| Security audit log (admin & security events) | Live |
| Work Trail (per-engagement agent & human activity) | Live |
| Microsoft 365 permission enforcement at query time | Live |
| Independent SOC 2 Type II (our own audit) | In preparation |
| Independent penetration test | Not yet |
Data residency map
Any processing outside the EU/EEA is always under a valid transfer mechanism.
| Data / process | Location | Notes |
|---|---|---|
| Core application data (accounts, projects, documents, embeddings) | Frankfurt, Germany | Hosted on Supabase |
| Application & frontend hosting | EU edge nodes | Vercel, European traffic routed within the EU |
| Standard model calls (OpenAI, Anthropic, Google Gemini) | United States | Covered by EU Standard Contractual Clauses |
| EU-hosted model calls (Enterprise option) | EU / EEA only | Via melious.ai, set up together with our team — no data leaves the EU |
| Microsoft Foundry model calls (Enterprise option) | EU (Germany West Central) | GPT and Claude models run on Drall's own Microsoft Azure AI Foundry resource, set up together with our team — no data leaves the EU |
EU-based by defaultCore infrastructure in Frankfurt
Who we work with
The infrastructure and model providers Drall relies on to operate, each bound by a Data Processing Agreement.
| Sub-processor | Purpose | Location | Certifications |
|---|---|---|---|
| Supabase / AWS | Database, file storage, vector search | Frankfurt, Germany (EU) | SOC 2 Type II, ISO/IEC 27001 |
| Vercel | Application hosting & CDN | Global edge, EU-prioritized | SOC 2 Type II, ISO/IEC 27001 |
| Microsoft | Microsoft 365 integration (Graph API) | Your firm's own Microsoft 365 tenant | SOC 1/2/3, ISO 27001, ISO 27018 |
| OpenAI, Anthropic, Google | Foundation model providers (standard routing) | United States | Barred from training on your data by API contract |
| melious.ai | EU-hosted foundation models (Enterprise option) | EU / EEA | Used only when EU-only routing is enabled |
| Microsoft Foundry | GPT and Claude models on Drall's own Azure AI Foundry resource (Enterprise option) | EU (Germany West Central) | Used only when Foundry routing is enabled; covered by the Microsoft Product Terms/DPA |
| Tavily | Web search for research workflows (standard routing) | United States | DPA in place |
| Linkup | Web search for research workflows (EU-hosted alternative to Tavily) | EU (France) | Used only when EU-hosted search is configured |
| Resend | Transactional and invitation emails | EU (Ireland) | DPA in place |
Security FAQ
What we do not claim yet
- No independent SOC 2 Type II certification of our own yet — our core infrastructure sub-processors are already certified.
- No completed third-party penetration test yet.
Contact
Security questions
For anything not covered here, or additional detail for your compliance review.
security@drall.aiVulnerability reporting
Safe harbor for good-faith researchers: no legal action for responsible disclosure, no access to other tenants’ data, no denial-of-service testing.
security@drall.aiIncident notification
Under GDPR Art. 33, we notify affected customers without undue delay, and no later than 72 hours after becoming aware of a verified breach.
security@drall.ai