EU Residency
All customer data is hosted in AWS eu-west-1 (Dublin, Ireland) – application servers, database, file storage, and outbound email.
Where your data lives, how we protect it, and the controls that govern it. · Last updated April 2026
Customer application data is stored exclusively in the European Union, with no replication outside the region.
All customer data is hosted in AWS eu-west-1 (Dublin, Ireland) – application servers, database, file storage, and outbound email.
Amazon RDS for the database, Amazon S3 for file storage, Amazon ECR/ECS for the application – all running in the same EU region.
We do not replicate customer data outside the EU. The only data that leaves the region is to the limited sub-processors listed below.
Every layer is encrypted by default – in transit and at rest – with the database isolated on a private network tier.
Every public endpoint enforces TLS 1.2 or higher. HTTP requests are automatically redirected to HTTPS – no plain-text traffic accepted.
AWS-managed encryption on RDS volumes, S3 objects, and EBS volumes. Encryption keys are rotated automatically.
The database lives on a private subnet, reachable only from the application tier. There is no direct internet path to your data.
Identity, authentication, and authorisation controls – built in, configurable, and audited.
SAML and OIDC SSO via WorkOS for enterprise customers. Centralise identity, enforce MFA, and revoke access from your IdP.
Passwords are stored as bcrypt hashes. Failed-attempt rate limiting protects against brute-force and credential-stuffing attacks.
Per-object ShareGrants with four permission tiers – control exactly who can read, comment, edit, or manage every process, form, or wiki.
Sensitive write operations are recorded with the user, endpoint, and timestamp. Audit log entries are retained for 30 days.
Per-session CSRF tokens guard every state-changing request. Cookie flags and origin checks defend against cross-site attacks.
Each company operates in its own logical tenant – no shared data, no cross-tenant access paths, even for support staff.
Security is built into how we ship code – automated scanning at every stage of the development pipeline.
Dependabot continuously monitors third-party libraries for known vulnerabilities and proposes upgrade pull requests automatically.
Every container image is scanned with Trivy in CI before deployment. Builds fail on critical CVEs in our image layer.
The application passes PHPStan level 10 with zero errors on every commit – strict typing and dead-code detection enforced in CI.
We process personal information in accordance with internationally recognised data protection laws and security frameworks.
Compliant with the EU General Data Protection Regulation. Mutual EU–UK adequacy means no SCCs are required for transfers between the regions.
Compliant with UK GDPR and the Data Protection Act 2018, supervised by the Information Commissioner's Office (ICO).
Compliant with California (CCPA / CPRA) and the comparable laws of Virginia, Colorado, Connecticut, Utah, Texas, and the growing list of US state privacy laws. Global Privacy Control (GPC) signals are honoured.
Compliant with South Africa's Protection of Personal Information Act, supervised by the Information Regulator.
SAQ-A self-attested (April 2026) – card data is handled by PayFast under their PCI-DSS Level 1 Service Provider attestation and never touches our servers. Hosted-redirect model; scope statement and SAQ-A available via the Security & Compliance Pack.
Working toward certification.
On the certification roadmap.
UK NCSC scheme – on the roadmap, prioritised when a UK gov, NHS, or council prospect requires it.
The third parties below process limited categories of data on our behalf. Standard Contractual Clauses (SCCs) are in place for unavoidable transfers outside the EU.
| Sub-processor | Purpose | Region |
|---|---|---|
| Amazon Web Services | Hosting, storage, document OCR (Textract) | Ireland (eu-west-1) |
| SendGrid (Twilio) | Transactional email – notifications, password resets, invites | United States (SCCs) |
| WorkOS | SSO identity brokering | United States (SCCs) |
| PayFast | Payment processing | South Africa |
| Anthropic / OpenAI | AI features (when enabled by you) – only the prompts you submit, never background data | United States (SCCs) |
| Sentry | Application error telemetry | United States – EU migration in progress |
A current sub-processor list and Data Processing Agreement (DPA) are available via our Security & Compliance Pack request form, or by e-mail to privacy@automize.co.za. We will notify customers at least 30 days before adding a new sub-processor or making a material change to an existing one, so you have time to object before the change takes effect.
Clear, predictable retention windows for every category of data we hold on your behalf.
Retained for the duration of your subscription.
Available for 30 days after termination on request.
Live data deleted within 30 days of termination; backups expire within 35 days.
Application and audit logs retained for 30 days.
Continuous backups, point-in-time recovery, and a public status page keep the platform available, recoverable, and verifiable.
AWS RDS automated backups: daily snapshots plus continuous transaction logs that capture changes to the second. All backups are encrypted with AWS KMS and stored in the same EU region as the live database.
The database can be restored to any second within the retention window – no manual snapshot juggling, no rolling back to the last nightly backup.
Check current platform health on our status page – database, cache, storage, and queue connectivity in real time.
How we detect, respond to, and notify you about security incidents.
Continuous monitoring of uptime, error rates, and latency. On-call engineers are paged on incident-grade signals.
Affected customers are notified within 72 hours of a confirmed personal-data breach, in line with GDPR Article 33.
Material incidents are followed by a written root-cause analysis, shared with affected customers along with remediation steps.
The Automize Bot is a desktop application that runs on machines you control. Your screens, files, and credentials stay with you.
The Bot runs on your workstation, VM, or data centre – not on our servers. Windows, Mac, and Linux are supported – including Windows Server for always-on, unattended deployments.
The Bot connects outbound to the platform in eu-west-1. We do not see the screens, files, or credentials it uses on your machine.
Only data you explicitly upload – process definitions, configured outputs, opt-in screenshots – reaches the platform.
See the full system requirements for supported operating systems, network rules, and machine specifications.
Reference legal documents and downloadable resources.
How we collect, use, store, and protect personal information.
The rights you can exercise (access, delete, correct, opt-out, limit) and how Global Privacy Control is honoured.
The form to submit a data subject access, deletion, correction, opt-out, or other privacy request.
The contractual terms that govern your use of the Automize platform.
The cookies and similar technologies we use, and how to manage them.
Self-serve request form for our DPA, security overview, sub-processor list, audit-log architecture, governance policy pack, and PCI-DSS SAQ-A – for vendor reviews, procurement, and auditors.
Embedded HackerOne submission form, response SLA, scope, and safe-harbour terms.
The exact folders, executables, and outbound endpoints your endpoint-protection and network teams need to allowlist the bot – with a rationale per entry, the EDR behaviours to expect, and a ready-to-run Defender snippet.
The licence terms that govern the use of bots downloaded from our marketplace.
Tenant-scoped record of every call to a critical endpoint – viewable by company admins, with filters and CSV export. Each row is part of a SHA-256 hash chain with nightly automated integrity verification and an admin-visible chain-status panel.
If you believe you have found a security vulnerability, submit it via the embedded HackerOne form on our security disclosure page, or by e-mail. We acknowledge reports within two business days and will keep you updated on progress.
Machine-readable contact information is published at /.well-known/security.txt in line with RFC 9116.
For privacy or data-protection questions: privacy@automize.co.za or privacy-request · General support: support@automize.co.za