Trust Center

Answers for your security review

Every control, data location, and sub-processor Drall relies on — documented in one place, with what we have not built yet stated just as plainly.

Download the DPA & TOMsLast updated: August 2026

Controls at a glance

TLS 1.2+ in transit, AES-256 at restLive
Two-factor authentication (TOTP), enforceable firm-wideLive
SSO — SAML 2.0 (set up together with our team)Live
Tenant isolation — Postgres row-level security on every queryLive
Per-project "Isolate" & "Confidential" togglesLive
Security audit log (admin & security events)Live
Work Trail (per-engagement agent & human activity)Live
Microsoft 365 permission enforcement at query timeLive
Independent SOC 2 Type II (our own audit)In preparation
Independent penetration testNot yet

Data residency map

Any processing outside the EU/EEA is always under a valid transfer mechanism.

Data / processLocationNotes
Core application data (accounts, projects, documents, embeddings)Frankfurt, GermanyHosted on Supabase
Application & frontend hostingEU edge nodesVercel, European traffic routed within the EU
Standard model calls (OpenAI, Anthropic, Google Gemini)United StatesCovered by EU Standard Contractual Clauses
EU-hosted model calls (Enterprise option)EU / EEA onlyVia melious.ai, set up together with our team — no data leaves the EU
Microsoft Foundry model calls (Enterprise option)EU (Germany West Central)GPT and Claude models run on Drall's own Microsoft Azure AI Foundry resource, set up together with our team — no data leaves the EU
EU-based by defaultCore infrastructure in Frankfurt

Who we work with

The infrastructure and model providers Drall relies on to operate, each bound by a Data Processing Agreement.

Sub-processorPurposeLocationCertifications
Supabase / AWSDatabase, file storage, vector searchFrankfurt, Germany (EU)SOC 2 Type II, ISO/IEC 27001
VercelApplication hosting & CDNGlobal edge, EU-prioritizedSOC 2 Type II, ISO/IEC 27001
MicrosoftMicrosoft 365 integration (Graph API)Your firm's own Microsoft 365 tenantSOC 1/2/3, ISO 27001, ISO 27018
OpenAI, Anthropic, GoogleFoundation model providers (standard routing)United StatesBarred from training on your data by API contract
melious.aiEU-hosted foundation models (Enterprise option)EU / EEAUsed only when EU-only routing is enabled
Microsoft FoundryGPT and Claude models on Drall's own Azure AI Foundry resource (Enterprise option)EU (Germany West Central)Used only when Foundry routing is enabled; covered by the Microsoft Product Terms/DPA
TavilyWeb search for research workflows (standard routing)United StatesDPA in place
LinkupWeb search for research workflows (EU-hosted alternative to Tavily)EU (France)Used only when EU-hosted search is configured
ResendTransactional and invitation emailsEU (Ireland)DPA in place

Security FAQ

What we do not claim yet

  • No independent SOC 2 Type II certification of our own yet — our core infrastructure sub-processors are already certified.
  • No completed third-party penetration test yet.

Contact

Security questions

For anything not covered here, or additional detail for your compliance review.

security@drall.ai

Vulnerability reporting

Safe harbor for good-faith researchers: no legal action for responsible disclosure, no access to other tenants’ data, no denial-of-service testing.

security@drall.ai

Incident notification

Under GDPR Art. 33, we notify affected customers without undue delay, and no later than 72 hours after becoming aware of a verified breach.

security@drall.ai