What a compliance or procurement reviewer needs before integrating the Prometiam company data API. We state only what is true today and label anything in progress as in progress.
All data is stored and processed in the EU — AWS eu-central-1 (Frankfurt), via Supabase. There is no replication outside the EU.
Supabase (database and auth, EU region), Cloudflare (website hosting, CDN, DDoS, DNS), Stripe (payments), Zoho Mail (transactional and support email).
We target high availability but do not contractually guarantee uninterrupted access on self-serve plans — see the Terms. Enterprise agreements can include a negotiated SLA.
Company data comes from official national registries: BORME (Spain), BODACC and the RNE (France), Companies House (United Kingdom), the CRO (Ireland), the KRS (Poland) and Enhetsregisteret at Brønnøysundregistrene (Norway, open data under the NLOD licence). Sanctions and export-control data comes from EU, UN, OFAC, UK OFSI, French gels and the US Consolidated Screening List.
Security reports: security@prometiam.com. Privacy and DPA requests: privacy@prometiam.com. A DPA is available on request.
| Item | Status |
|---|---|
| GDPR | Compliant — EU residency, data-subject rights process, documented lawful basis |
| SOC 2 Type II | In progress — independent audit under way. Not yet certified; the report will be published when it exists. |
| ISO 27001 | Aligned, certification pending — controls mapped, not yet certified |
| PCI DSS | Handled by Stripe — Prometiam never sees or stores card data |
| Encryption | TLS 1.3 in transit; encryption at rest |
| Authentication | Bearer API keys, stored only as SHA-256 hashes; revocable and rotatable from the dashboard |
| Processor | Purpose | Region |
|---|---|---|
| Supabase | Database, authentication, edge compute | EU (Frankfurt) |
| Cloudflare | Website hosting, CDN, DDoS protection, DNS | Global edge |
| Stripe | Payments and subscription billing | EU / global |
| Zoho Mail | Transactional and support email | EU |