Trust center
What a CISO or DPO needs to review, with the real status.
One place for due diligence: what is done, what is in progress and which documents you can request. If something is missing, ask us and we will add it.
Status summary
- In progress ENS / ISO 27001 certification Not certified. Joint ENS Media + ISO 27001 audit targeted for Q2–Q3 2027.
- By default Where the platform runs Microsoft Azure, Spain Central (Madrid). Those services’ ENS Alto certification is Microsoft’s.
- By default Residency attestation An Ed25519-signed token on every response, verifiable with public keys.
- By default Data handling Metadata only by default. Staff have no access to content.
- Published Sub-processors Public preliminary list, per residency tier.
- On request Data processing agreement Available on request; under counsel review.
- Scheduled Penetration test External, scheduled before the first customer goes live.
- Published Vulnerability disclosure Contact and policy in security.txt.
Certification. Situra is not certified yet; this is the plan.
We design for ENS category Alta and certify category Media first, which covers most public buyers. The audit needs evidence of the system in operation, so it depends on the beta starting on time.
Security architecture. A summary for review.
This is the design of the platform we are building; the external penetration test will verify it before the first go-live.
- Keys and secrets
API keys are shown once and we store only an HMAC. Provider credentials and per-tenant data keys in Azure Key Vault (Managed HSM).
- Tenant isolation
Postgres row-level security with FORCE on every customer table.
- Audit log
Append-only, hash-chained, verifiable, exportable as JSONL and streamable to the organisation’s SIEM.
- Staff
Back office on a private network, SSO with hardware keys, just-in-time privileges and database-enforced four-eyes approval.
- Supply chain
Signed images, an SBOM per release, pinned dependencies, SAST/DAST and a second human review of critical code.
- Customer access
Mandatory second factor (passkey or TOTP) with recovery codes; each organisation can require phishing-resistant MFA. Console sign-in via OIDC and SCIM for verified domains. SSO with each organisation’s own identity provider: planned.
Residency attestation. Signed evidence, per request, of where it was processed.
Every gateway response carries x-situra-attestation, a signed token the organisation’s team can archive and verify on its own, without relying on the console or on Situra.
Data handling. The minimum needed to operate and bill.
- By default
- Metadata only: who, model, tokens, cost, latency, status and route. No prompts or responses.
- Content logging
- Opt-in per project, 0–365 days of retention, encrypted with AES-256-GCM under your organisation’s data key.
- Crypto-shredding
- Deleting the organisation’s data key makes all of its logged content unreadable.
- Situra staff
- No internal API returns content. Every staff access to your organisation’s data requires a reason and lands in your audit log.
- Zero retention
- Zero-retention routes only where the provider offers it; the console shows which.
- Where
- Metadata, optional content and keys in Azure Spain Central. The model runs wherever the route chosen by the project’s tier points.
Sub-processors. Who may process data, by tier.
A model provider only receives data when a project’s tier and model route to it. Preliminary list: the binding one is annexed to the DPA.
ES Spain routes only
Possible model providers
- Google Cloud (Vertex AI)
- Microsoft (Azure OpenAI) · to verify
- Microsoft (Foundry) · to verify
- Self-hosted open weights (Situra, on Azure) · to verify
EU EU and Spain routes
Possible model providers
- Amazon Web Services (Bedrock)
- Google Cloud (Vertex AI)
- Microsoft (Azure OpenAI)
- Microsoft (Foundry) · to verify
- Mistral AI
- Self-hosted open weights (Situra, on Azure)
Global Any route, including global ones
Possible model providers
- Amazon Web Services (Bedrock)
- Anthropic
- Google Cloud (Vertex AI)
- Microsoft (Azure OpenAI)
- Microsoft (Foundry) · to verify
- Mistral AI
- OpenAI
- Self-hosted open weights (Situra, on Azure)
Platform (every tier)
- Microsoft Azure — hosting, Spain Central
- Stripe — payments (no request content)
Procurement pack. What can be requested today.
What a public administration usually asks for before contracting. Nothing downloads from this page: available documents are sent on request.
- On request Request
Data processing agreement (DPA) template
Under counsel review.
- Published View list
Sub-processor list
Public and preliminary; the binding one is annexed to the DPA.
- Published View
Security architecture summary
This page and the Security page.
- On request Request
Sample invoice in Facturae format
Facturae invoices are already generated; electronic signing and FACe submission are in development.
- In preparation
ENS categorisation and statement of applicability
Planned for October–November 2026; can be shared under NDA.
- Scheduled
External penetration test report
Before a customer’s first go-live; executive summary under NDA once it exists.
- In preparation
Data protection impact assessment (content logging)
In preparation.
- On request Request
SBOM
Generated per release.
- In progress Roadmap
ENS / ISO 27001 certificates
Once they exist. Audit targeted for Q2–Q3 2027.
Or write to situra@syntheris.com
Vulnerability disclosure.
Write to us before going public and give us reasonable time to fix it. We answer in Spanish or English. Please do not access third parties’ data or degrade the service while testing.
- Contact
- security@situra.ai
- Machine-readable policy
- /.well-known/security.txt