Skip to content

Datapunkt Security & Compliance

Welcome to the comprehensive compliance and security integration guide for Datapunkt. This document is designed to help data engineers, data architects, and security compliance officers understand how Datapunkt safeguards sensitive database schemas, architectural blueprints, and business metadata, enforces zero-data model training, and aligns with strict European data regulations.

Note: While Datapunkt operates with a decentralized control panel and modular agents, security is managed centrally. This guide highlights our active privacy filters, secure deployment models, and verification documentation available for vendor risk assessments (VRAs).

Data Residency & Infrastructure

Enterprise data architectures require explicit regional hosting compliance to meet GDPR and corporate data governance mandates.

  • Primary Hosting Infrastructure: All standard multi-tenant SaaS environments are hosted in Germany (AWS EU-Central-1 region, Frankfurt). No client data is stored or processed outside the European Economic Area (EEA) by default.
  • Database Isolation: Datapunkt utilizes logical database isolation per workspace tenant. This means that even in the standard SaaS tier, your data belongs to an isolated container and cannot be accessed, leaked, or indexed by search query sweeps from other accounts.
  • Backup & Redundancy: Encrypted snapshots are taken every 24 hours and retained for 30 days. Backups are stored inside the same regional infrastructure and are subject to the identical AES-256 encryption standards.

Flexible Deployment Models

Enterprise organizations have differing risk appetites, compliance frameworks, and IT architectures. Datapunkt supports three distinct deployment configurations:

1. Standard Multi-Tenant SaaS

  • Target Audience: Analytics teams, mid-market data departments, and lean compliance teams.
  • Security Posture: Immediate access with standard enterprise guards. Data resides in secure, logically separated virtual databases within our main AWS Frankfurt cluster.

2. Dedicated Single-Tenant Cloud

  • Target Audience: Large corporate data engineering teams, Tier-1 banking data teams, and high-security government enterprises.
  • Security Posture: Datapunkt deploys a dedicated, isolated instance of the platform inside a private Virtual Private Cloud (VPC) on AWS or Azure in your preferred geographic region (e.g., EU, US, or APAC). This isolates your data on both the database and application levels.

3. Hybrid Gateway / Local Anonymisation

  • Target Audience: Highly regulated firms operating under strict national professional secrecy laws or stringent data protection standards (e.g., banking regulations, healthcare standards, or GDPR).
  • Security Posture: An on-premise proxy gateway is deployed inside your local network infrastructure. All database connections, schemas, and queries are scrubbed of sensitive PII or raw transactional data before they pass your corporate firewall, ensuring that external LLM APIs only receive fully anonymized metadata and non-privileged text vectors.

Security & Compliance Certifications

The badges displayed in the Security Center correspond to active, audited certifications held by our host infrastructure and application architecture:

  • ISO/IEC 27001: Demonstrates that Datapunkt maintains a rigorous Information Security Management System (ISMS) governing software deployment, physical security, access management, and vulnerability resolution.
  • SOC 2 Type II: Audited annually by an independent third-party firm, confirming the operational effectiveness of our security, availability, and confidentiality controls.
  • GDPR Compliant: Designed specifically to align with EU regulations. We offer standard Data Processing Addendums (DPAs) that incorporate EU Standard Contractual Clauses (SCCs).

Secure Documentation Library

At the bottom of the Security Center interface, you will find a secure download panel. These files are provided directly from our repository to accelerate your internal vendor risk assessment (VRA):

Document TitleRecommended ReviewerPrimary Use / Contents
Datapunkt Security Whitepaper.pdfChief Information Security Officer (CISO)Deep architectural overview, network diagrams, threat modeling, and incident response runbooks.
ISO/IEC 27001 Audit Certificate.pdfIT Audit & Compliance LeadFormal proof of our active information security certification.
SOC 2 Type II Auditor's Report.pdfVendor Risk Assessor / IT AnalystDetailed control matrix testing results regarding data safety and operational stability.
Data Processing Addendum (DPA).pdfLegal Counsel / Privacy OfficerLegal agreement establishing GDPR-compliant data processing, standard clauses, and subprocessors.
Penetration Test Summary.pdfSecurity Operations (SecOps)Independent third-party vulnerability assessment findings and remediation confirmation.

To download any document, hover over the document row in the UI and click the Download icon.

Best Practices for Vendor Onboarding

If you are an IT Administrator evaluating Datapunkt for your organization, we recommend following these steps:

  1. Configure Single Sign-On (SSO): Integrate your workspace with Okta, Microsoft Entra ID (Azure AD), or Google Workspace early in the settings panel to ensure compliance with your corporate password policies and MFA defaults.
  2. Assign Role-Based Access Control (RBAC): Use the workspace settings to restrict database connection setup, API configurations, and security settings to authorized users only.
  3. Engage with our Enterprise Security Team: If your organization requires a Single-Tenant deployment or custom anonymization gateways, bypass automated configurations and contact our enterprise deployment team directly at info@datapunkt.com to acquire custom architectural blueprints.

Contact Us