Built for regulated operations.
Engineered intelligence means agents with a run log and a human gate — the same discipline applies to how we hold your data. Below is our current posture, not a marketing claim.
Trust posture
SOC 2 Type II
Audit in progress.
Fieldwork underway with an independent auditor. Report expected on completion — we will not claim it early.
ISO 27001-aligned controls
Controls mapped, certification not yet pursued.
Access management, change control, and incident response follow the framework's structure today.
SSO / SAML + SCIM
Enterprise identity, not a shared login.
Provision and deprovision through your IdP. Okta and Entra ID verified; others on request.
Role-based access
Permissions follow the org chart, not the ticket.
Scoped by site, role, and module — a planner is not a plant manager.
Encryption everywhere
AES-256 at rest, TLS 1.3 in transit.
Keys managed per-tenant. No shared secrets across client environments.
Audit logging & retention
Every state change is attributable.
Who, what, when — retained per the schedule below, exportable on request.
Data handling
Where data lives
Primary region is EU (Frankfurt) with a US (Virginia) option for clients that require it. We do not move a tenant's region without written agreement.
Tenancy model
Single-tenant per client at the database layer — dedicated schema, not a shared table with a tenant_id column. No client queries another client's rows by construction.
Retention defaults
Operational records: retained for the contract term plus 90 days, then purged on request. Audit logs: 12 months rolling, extendable for regulated clients. Backups: 30-day point-in-time.
PII handling
Minimised at intake — we ask for what the workflow needs, not what a form template happens to include. Technician and requester PII is scoped to the records they touch, never bulk-exported by default.
Subprocessors
Vendors that can touch client data in the course of running the platform. Updated as the list changes.
| Vendor | Purpose | Region | DPA status |
|---|---|---|---|
| AWS (Frankfurt, eu-central-1) | Application hosting & storage | EU | DPA signed |
| Cloudflare | CDN & DDoS protection | Global edge | DPA signed |
| Datadog | Infrastructure monitoring | EU | DPA signed |
| Sentry | Error tracking (metadata only) | EU | DPA signed |
| Postmark | Transactional email | US | In evaluation |
| Anthropic API | Agent reasoning (no training on client data) | US | DPA signed |
Incident response
A severity ladder with defaults, not a promise we will never have an incident.
Sev 1 — Critical
Data exposure or full outage on a production tenant.
RTO 4h · RPO 1h
Sev 2 — High
Degraded service or a single-tenant outage.
RTO 24h · RPO 4h
Sev 3 — Moderate
Non-blocking defect with a workaround.
RTO 5 business days · n/a
Talk to us about your requirements
Regulated environments come with their own audit checklist. Bring it — we will tell you what we meet today and what needs a conversation.
This posture reflects our current commitments, not a certification claim. Live report: security@adqueo.com
Have an operation that generic software can't fit?
Bring the loop that is currently a spreadsheet. We will say whether this is custom software, a product, an agent — or not ours.