Skip to main content

Trust center

Security and privacy, built in Europe

Replio is built and operated in the European Union. This page explains where your training data lives, how it is protected and which rules we follow.

Service status

All systems operational

Checked automatically every minute.

Compliance

Two European frameworks shape how Replio is designed and run.

GDPR

The EU's data protection regulation. Replio acts as your processor and gives you the tools to meet your own obligations.

  • Data processing agreement based on the European Commission's standard clauses, available to every customer
  • Managers and trainees can export and delete their data in the product
  • Data hosted in the EU, with documented safeguards for any transfer outside it

EU AI Act

The EU's regulation on artificial intelligence. Replio is a training tool where a person stays in charge.

  • Trainees always know they are talking to an AI
  • Scores and feedback support a manager's judgment and never replace it
  • Not intended for recruitment, promotion or dismissal decisions

Replio holds no security certification of its own yet. Our hosting and AI providers are ISO 27001 certified and make SOC 2 reports available, and we share those references on request.

Read the privacy policy

Where your data lives

Replio runs on a small number of established providers, configured for the European Union.

European Union: where the application, database, files and AI processing run

Netherlands: the Google Cloud region used for knowledge retrieval

Frankfurt: the database region (Neon on AWS)

Application

Cloudflare

EU

The web app and API run on Cloudflare, with application compute pinned to the EU.

Database

Neon (Databricks)

EU

Accounts, organizations and training results are stored in an EU region, with automated backups.

Files

Cloudflare R2

EU

Recordings and uploaded documents are stored in a bucket under Cloudflare's EU jurisdiction and served only through short-lived signed links.

AI processing

Google Cloud Vertex AI

EU

Voice conversations, transcripts, session analysis and document processing run in Google Cloud's EU locations. Your data is not used to train AI models.

Some supporting operations, such as network edge logs and optional add-ons, can involve processing outside the EU under Standard Contractual Clauses. The privacy policy and our data processing agreement describe them.

Security controls

The measures below are in place today.

Data protection

  • Encryption in transit and at rest
  • Integration credentials encrypted again at the application level
  • No file is publicly readable

Access control

  • Role-based access, including read-only roles limited to chosen projects
  • Enterprise single sign-on (SAML or OIDC)
  • Each organization's data is isolated from every other

Operations

  • Continuous monitoring with operator alerts
  • Container images scanned for vulnerabilities before every production deployment
  • Database backups with point-in-time recovery

Privacy by design

  • AI providers receive only the data a feature needs
  • Server logs kept 7 to 30 days, without audio or transcript content
  • Breach notification process in line with the GDPR

Need more detail?

Ask for our data processing agreement, the sub-processor list or answers to your security questionnaire. We reply to every request.

Contact us