Skip to main content

Security & data protection

Literate is built EU-resident, pseudonym-first, and designed for IT and security teams to approve quickly.

Hosting

EU region only: Vercel EU edge, Postgres in EU jurisdiction, Cloudflare R2 EU bucket.

Data minimisation

SSO mode stores no staff PII — only pseudonyms derived via HMAC of the IdP sub claim.

Encryption

TLS 1.3 in transit, AES-256 at rest. Database backups encrypted, EU region, 30-day retention.

Sub-processors

Publicly listed with locations and SCCs where applicable.

Certifications

Cyber Essentials Plus (in progress), ISO 27001 (planned), SOC 2 (planned).

Incident response

72-hour customer notification commitment per UK GDPR Article 33.

Penetration testing

Annual third-party testing scheduled post-launch.

Bug bounty

Reports to security@literate.eu acknowledged within 24h.

DRAFT — this page is illustrative of what the live site will publish. Replace placeholders before launch.