Trust & Security — Prometiam
What a compliance or procurement reviewer needs before integrating the Prometiam company data API. We state only what is true today and label anything in progress as in progress.
Data residency
All data is stored and processed in the EU — AWS eu-central-1 (Frankfurt), via Supabase. There is no replication outside the EU.
Certifications and posture
- GDPR — EU data residency, data-subject rights process, documented lawful basis.
- SOC 2 — independent Type II audit in progress. Not yet certified; we will publish the report when it exists.
- ISO 27001 — controls aligned, certification pending. Not yet certified.
- PCI DSS — card payments are handled entirely by Stripe. Prometiam never sees or stores card data.
- Encryption — TLS 1.3 in transit, encryption at rest.
Sub-processors
Supabase (database and auth, EU region), Cloudflare (website hosting, CDN, DDoS, DNS), Stripe (payments), Zoho Mail (transactional and support email).
Availability
We target high availability but do not contractually guarantee uninterrupted access on self-serve plans — see the Terms. Enterprise agreements can include a negotiated SLA.
Data sources
Company data comes from official national registries: BORME (Spain), BODACC and the RNE (France), Companies House (United Kingdom), the CRO (Ireland) and the KRS (Poland). Sanctions and export-control data comes from EU, UN, OFAC, UK OFSI, French gels and the US Consolidated Screening List.
Contact
Security reports: security@prometiam.com. Privacy and DPA requests: privacy@prometiam.com. A DPA is available on request.
Privacy policy · Terms · Get a free API key