Trust center
Security and privacy, built in Europe
Replio is built and operated in the European Union. This page explains where your training data lives, how it is protected and which rules we follow.
Service status
All systems operational
Checked automatically every minute.
Compliance
Two European frameworks shape how Replio is designed and run.
GDPR
The EU's data protection regulation. Replio acts as your processor and gives you the tools to meet your own obligations.
- Data processing agreement based on the European Commission's standard clauses, available to every customer
- Managers and trainees can export and delete their data in the product
- Data hosted in the EU, with documented safeguards for any transfer outside it
EU AI Act
The EU's regulation on artificial intelligence. Replio is a training tool where a person stays in charge.
- Trainees always know they are talking to an AI
- Scores and feedback support a manager's judgment and never replace it
- Not intended for recruitment, promotion or dismissal decisions
Replio holds no security certification of its own yet. Our hosting and AI providers are ISO 27001 certified and make SOC 2 reports available, and we share those references on request.
Read the privacy policyWhere your data lives
Replio runs on a small number of established providers, configured for the European Union.
European Union: where the application, database, files and AI processing run
Netherlands: the Google Cloud region used for knowledge retrieval
Frankfurt: the database region (Neon on AWS)
Application
Cloudflare
The web app and API run on Cloudflare, with application compute pinned to the EU.
Database
Neon (Databricks)
Accounts, organizations and training results are stored in an EU region, with automated backups.
Files
Cloudflare R2
Recordings and uploaded documents are stored in a bucket under Cloudflare's EU jurisdiction and served only through short-lived signed links.
AI processing
Google Cloud Vertex AI
Voice conversations, transcripts, session analysis and document processing run in Google Cloud's EU locations. Your data is not used to train AI models.
Some supporting operations, such as network edge logs and optional add-ons, can involve processing outside the EU under Standard Contractual Clauses. The privacy policy and our data processing agreement describe them.
Security controls
The measures below are in place today.
Data protection
- Encryption in transit and at rest
- Integration credentials encrypted again at the application level
- No file is publicly readable
Access control
- Role-based access, including read-only roles limited to chosen projects
- Enterprise single sign-on (SAML or OIDC)
- Each organization's data is isolated from every other
Operations
- Continuous monitoring with operator alerts
- Container images scanned for vulnerabilities before every production deployment
- Database backups with point-in-time recovery
Privacy by design
- AI providers receive only the data a feature needs
- Server logs kept 7 to 30 days, without audio or transcript content
- Breach notification process in line with the GDPR
Need more detail?
Ask for our data processing agreement, the sub-processor list or answers to your security questionnaire. We reply to every request.
Contact us