Enquant
Security & Trust

Honest about what's in place today

Enquant operates in environments where data protection is non-negotiable. This page describes the controls that exist today and the items still on the roadmap — we don't claim certifications or programs we haven't earned.

Principles

How we approach customer data

The principles that shape every architectural decision.

Code-enforced tenant isolation

Every database query is scoped to your tenant by code-enforced utilities. There is no path for one customer's data to enter another customer's optimization run, and customer-side role-based access controls what each of your planners can do inside Enquant.

Encryption in transit and at rest

Customer data is encrypted at rest by our database provider and in transit with TLS 1.2 or higher. Secrets live in our hosting platform's encrypted secret store — never in code or environment files.

Infrastructure

Where your data lives, and how it's protected

EU-hosted by default

Customer data is processed and stored in EU data centres unless a customer specifically requests another region for their own compliance reasons.

Logical production isolation

Each customer's data is logically isolated by our tenant utilities. Compute and storage tenancy is configurable per customer; dedicated tenancy is available for enterprises that require it.

Backups and retention

Encrypted backups run daily with point-in-time recovery within a defined retention window. Data deletion on customer request is honoured within the contractual SLA.

Compliance

Where we are today

We name what we have and what we don't, rather than implying certifications or programs we haven't earned.

GDPRAligned
We process personal data under GDPR. EU-only deployments can be scoped contractually for customers with strict residency requirements.
Customer DPAsOn request
We are happy to review and sign customer-provided Data Processing Agreements. As an early-stage company we do not yet maintain a standard DPA template — that lands alongside our first paid contract.
External penetration testingOn the roadmap
We will commission an external penetration test ahead of our first paid SaaS contract. Until then, no third-party report is available.
Documented sub-processorsOn the roadmap
Cloud infrastructure, observability, and transactional email vendors are our current sub-processors. A formal documented list will be published alongside our first paid contract.
SOC 2 Type IIOn the roadmap
Targeted for the year following our first full year of live SaaS operations. Until then, we share equivalent control mappings on request.
FAQ

Security questions

The questions enterprise procurement and security teams ask first.

Need to dig deeper?

Reach out and we'll answer specific questions on tenant isolation, hosting, and data handling — directly with the team that built it.

Talk to us about security
Enquant

Operational decision intelligence for supply chain.

All systems normal

© 2026 Enquant