Enquant operates in environments where data protection is non-negotiable. This page describes the controls that exist today and the items still on the roadmap — we don't claim certifications or programs we haven't earned.
The principles that shape every architectural decision.
Every database query is scoped to your tenant by code-enforced utilities. There is no path for one customer's data to enter another customer's optimization run, and customer-side role-based access controls what each of your planners can do inside Enquant.
Customer data is encrypted at rest by our database provider and in transit with TLS 1.2 or higher. Secrets live in our hosting platform's encrypted secret store — never in code or environment files.
Customer data is processed and stored in EU data centres unless a customer specifically requests another region for their own compliance reasons.
Each customer's data is logically isolated by our tenant utilities. Compute and storage tenancy is configurable per customer; dedicated tenancy is available for enterprises that require it.
Encrypted backups run daily with point-in-time recovery within a defined retention window. Data deletion on customer request is honoured within the contractual SLA.
We name what we have and what we don't, rather than implying certifications or programs we haven't earned.
The questions enterprise procurement and security teams ask first.
Reach out and we'll answer specific questions on tenant isolation, hosting, and data handling — directly with the team that built it.