Trust, Security & Reliability
Your documents are sensitive. We designed our system so your files stay in the EU, access is tightly controlled, and links expire fast. Below is exactly how we keep your data safe: what we do today and what’s being rolled out next.
Data stays in the EU
- Today: We host your data in Microsoft Azure EU regions. Azure offers strong data-residency commitments for EU customers. Data Residency in Azure
- Rolling out next: A public page listing our exact Azure regions for each service component.
We don’t use your data to train AI models
- Today: When we use Azure OpenAI, your prompts and documents are not used to train models. This is Microsoft’s policy for Azure OpenAI. Azure OpenAI FAQ
- Rolling out next: A self-serve toggle so enterprise customers can download an audit summary of model calls tied to their tenant.
Private, not public: how we connect to storage and keys
- Today: Documents are stored in private Azure Blob Storage. Access is controlled via Azure identities (no shared passwords). Short-lived, read-only download links are generated when you need to view a file.
- Rolling out next: Private Endpoints/Private Link everywhere (Storage, App, Key Vault) so traffic stays on Microsoft’s private backbone instead of the public internet. Azure Private Link
Secrets are locked in a vault
- Today: We keep secrets out of code and store them in Azure Key Vault with least-privilege access. Key Vault best practices
- Rolling out next: Automated key rotation runbooks and dashboards that confirm rotations completed on schedule.
Encryption in transit & at rest
- Today: All connections use HTTPS/TLS. Files at rest are encrypted by Azure Storage.
- Rolling out next: HSTS and a stricter Content Security Policy (CSP) across all apps to further reduce browser-based risks.
Sign in with your Microsoft account
- Today: You sign in through Microsoft Entra ID, the same account system your company already uses for Outlook and Teams. We never see or store your password, your own IT department's security rules (including multi-factor authentication) apply automatically, and when an employee leaves your company, their access to Ceyltech ends the moment IT disables their Microsoft account.
Minimal access, short windows
- Today: Employees don’t have default access to your content. Access (when needed for support) is time-limited and logged. Document links use short-lived SAS URLs that expire automatically.
- Rolling out next: Customer-visible access logs showing when support accessed a file (if ever), with a reason.
We process long jobs safely in the background
- Today: Heavy tasks (OCR, AI extraction) run in background workers so the website stays responsive, and failed jobs can be retried without data loss.
- Rolling out next: Per-job progress indicators and automatic deduplication if the same file is uploaded twice.
Retention & deletion
- Today: We apply retention rules so temporary files are auto-deleted after a short period. You can request deletion of processed data at any time.
- Rolling out next: A retention settings page where you pick how long we keep raw uploads vs. processed outputs.
Monitoring, alerts & reliability
- Today: We monitor uptime, errors and performance. If something degrades, our team is alerted immediately.
- Rolling out next: A public status page with historical uptime and incident post-mortems.
Compliance posture (EU-friendly by design)
- Today: We build on Microsoft Azure’s broad compliance portfolio (ISO, SOC, GDPR-aligned services). We maintain records of processing and use multi-factor authentication (MFA) for operator access. Azure Compliance
- Rolling out next: Customer-signed Data Processing Agreement (DPA) downloads from your admin portal and a simple list of sub-processors (primarily Microsoft Azure services in the EU).
Security practices we follow
Today:
- Principle of Least Privilege for systems and staff
- Mandatory MFA and Conditional Access for administrator accounts
- Rate limiting and abuse protection on expensive endpoints
- Regular updates/patching and dependency pinning
Rolling out next:
- Optional antivirus scanning on upload, and periodic third-party security reviews.
Your controls
- Today: Request data exports or deletion at any time via support.
- Rolling out next: Self-service deletion and export tools, plus privacy preferences in your account.
Questions? Need a security review?
We’re happy to complete customer security questionnaires and provide architecture overviews under NDA. Contact: security@ceyltech.com
Why we chose Azure for EU customers
Microsoft’s documentation explains EU data residency, the EU Data Boundary, and private networking options that keep traffic off the public internet. These are the foundations we’re building on. Learn more