Trust center

What a CISO or DPO needs to review, with the real status.

One place for due diligence: what is done, what is in progress and which documents you can request. If something is missing, ask us and we will add it.

Certification. Situra is not certified yet; this is the plan.

We design for ENS category Alta and certify category Media first, which covers most public buyers. The audit needs evidence of the system in operation, so it depends on the beta starting on time.

Compliance roadmap, with dates

Security architecture. A summary for review.

This is the design of the platform we are building; the external penetration test will verify it before the first go-live.

  • Keys and secrets

    API keys are shown once and we store only an HMAC. Provider credentials and per-tenant data keys in Azure Key Vault (Managed HSM).

  • Tenant isolation

    Postgres row-level security with FORCE on every customer table.

  • Audit log

    Append-only, hash-chained, verifiable, exportable as JSONL and streamable to the organisation’s SIEM.

  • Staff

    Back office on a private network, SSO with hardware keys, just-in-time privileges and database-enforced four-eyes approval.

  • Supply chain

    Signed images, an SBOM per release, pinned dependencies, SAST/DAST and a second human review of critical code.

  • Customer access

    Mandatory second factor (passkey or TOTP) with recovery codes; each organisation can require phishing-resistant MFA. Console sign-in via OIDC and SCIM for verified domains. SSO with each organisation’s own identity provider: planned.

Full security design

Residency attestation. Signed evidence, per request, of where it was processed.

Every gateway response carries x-situra-attestation, a signed token the organisation’s team can archive and verify on its own, without relying on the console or on Situra.

How it is signed and how to verify it

Data handling. The minimum needed to operate and bill.

By default
Metadata only: who, model, tokens, cost, latency, status and route. No prompts or responses.
Content logging
Opt-in per project, 0–365 days of retention, encrypted with AES-256-GCM under your organisation’s data key.
Crypto-shredding
Deleting the organisation’s data key makes all of its logged content unreadable.
Situra staff
No internal API returns content. Every staff access to your organisation’s data requires a reason and lands in your audit log.
Zero retention
Zero-retention routes only where the provider offers it; the console shows which.
Where
Metadata, optional content and keys in Azure Spain Central. The model runs wherever the route chosen by the project’s tier points.

Sub-processors. Who may process data, by tier.

A model provider only receives data when a project’s tier and model route to it. Preliminary list: the binding one is annexed to the DPA.

ES Spain routes only

Possible model providers

  • Google Cloud (Vertex AI)
  • Microsoft (Azure OpenAI) · to verify
  • Microsoft (Foundry) · to verify
  • Self-hosted open weights (Situra, on Azure) · to verify

EU EU and Spain routes

Possible model providers

  • Amazon Web Services (Bedrock)
  • Google Cloud (Vertex AI)
  • Microsoft (Azure OpenAI)
  • Microsoft (Foundry) · to verify
  • Mistral AI
  • Self-hosted open weights (Situra, on Azure)

Global Any route, including global ones

Possible model providers

  • Amazon Web Services (Bedrock)
  • Anthropic
  • Google Cloud (Vertex AI)
  • Microsoft (Azure OpenAI)
  • Microsoft (Foundry) · to verify
  • Mistral AI
  • OpenAI
  • Self-hosted open weights (Situra, on Azure)

Platform (every tier)

  • Microsoft Azure — hosting, Spain Central
  • Stripe — payments (no request content)

Full sub-processor list

Procurement pack. What can be requested today.

What a public administration usually asks for before contracting. Nothing downloads from this page: available documents are sent on request.

  • Data processing agreement (DPA) template

    Under counsel review.

    On request Request
  • Sub-processor list

    Public and preliminary; the binding one is annexed to the DPA.

    Published View list
  • Security architecture summary

    This page and the Security page.

    Published View
  • Sample invoice in Facturae format

    Facturae invoices are already generated; electronic signing and FACe submission are in development.

    On request Request
  • ENS categorisation and statement of applicability

    Planned for October–November 2026; can be shared under NDA.

    In preparation
  • External penetration test report

    Before a customer’s first go-live; executive summary under NDA once it exists.

    Scheduled
  • Data protection impact assessment (content logging)

    In preparation.

    In preparation
  • SBOM

    Generated per release.

    On request Request
  • ENS / ISO 27001 certificates

    Once they exist. Audit targeted for Q2–Q3 2027.

    In progress Roadmap
Request documents

Or write to

Vulnerability disclosure.

Write to us before going public and give us reasonable time to fix it. We answer in Spanish or English. Please do not access third parties’ data or degrade the service while testing.

Contact
Machine-readable policy
/.well-known/security.txt