Built for regulated operations.
We do not claim certifications of our own. We run on infrastructure certified by its providers and apply verifiable controls on top. Below is our real posture, not a marketing claim.
Trust posture
Certified infrastructure
The certifications belong to our providers, not to us.
Cloudflare (SOC 2 Type II, ISO 27001 and ISO 27701) at the edge; Netcup (ISO 27001 and ISO 27701, data centers in Germany) for compute and data. Our part is the controls we apply on that base.
Role-based access (RBAC)
Permissions follow the org chart, not the ticket.
Scoped by company, site, role, and module. A planner is not a plant manager, and the software enforces it.
Per-company isolation
Each company sees only its own rows, by construction.
Row-Level Security (RLS) in PostgreSQL: the signed token's identity decides which rows exist for that session. Not an application filter that can be forgotten.
Encryption in transit
TLS 1.3 on every connection.
Managed certificates; no product traffic in the clear. At rest, under the encryption controls of our infrastructure providers.
Strong authentication (2FA)
Second factor available and enforceable by policy.
Centralized identity; access to each product is granted and revoked explicitly, not by shared login.
Audit logging
Every state change is attributable.
Who, what, when — retained per the schedule below. Traceability is also our evidence against any claim.
Data handling
Where data lives
Product data lives in Netcup data centers in Germany (EU). The edge — CDN, WAF, and DDoS protection — is Cloudflare, with global presence. We do not move a company's region without written agreement.
Tenancy model
Multi-company with isolation by Row-Level Security in PostgreSQL: each company has its own membership and its own rows, and no query crosses into another's by construction. Identity comes from a signed token, not a parameter the client can alter.
Retention defaults
Operational records: retained for the contract term plus 90 days, then purged on request. Audit and policy-acceptance logs: 12 months rolling, extendable for regulated clients. Backups: provider point-in-time.
PII handling
Minimised at intake — we ask for what the workflow needs, not what a form template happens to include. Technician and requester PII is scoped to the records they touch, never bulk-exported by default.
Subprocessors
Vendors that can touch client data in the course of running the platform. This is the real list; updated when it changes.
| Vendor | Purpose | Region | DPA status |
|---|---|---|---|
| Cloudflare | Edge, CDN, WAF/DDoS, Workers and D1 | Global | SOC 2 Type II · ISO 27001/27701 |
| Netcup GmbH | Compute, PostgreSQL and storage | Germany (EU) | ISO 27001 · ISO 27701 |
| Anthropic (API) | Agent reasoning | USA | No training on client data |
| Resend | Transactional email | USA | Email subprocessor (DPA) |
Incident response
Internal targets with a severity ladder, not a promise we will never have an incident. We notify affected companies of confirmed breaches without undue delay, aligned with the 72-hour deadline of Legislative Decree No. 144 (El Salvador Personal Data Protection Law).
Sev 1 — Critical
Data exposure or full outage in production.
RTO 4h · RPO 1h
Sev 2 — High
Degraded service or a single-company outage.
RTO 24h · RPO 4h
Sev 3 — Moderate
Non-blocking defect with a workaround.
RTO 5 business days · n/a
Talk to us about your requirements
Regulated environments come with their own audit checklist. Bring it — we will tell you what we meet today and what needs a conversation.
This posture reflects real controls and our infrastructure providers' certifications, not certifications of Adqueo's own. Contact: daniel@adqueo.com
See the software. Or tell us the loop that does not fit.
The suite lives here. If the loop does not fit, let’s talk about custom software.