Etainabl is built with security-first principles. We handle sensitive energy and financial data on behalf of our customers, and we take that responsibility seriously.
All customer data is hosted on AWS, with the primary region in the EU (Ireland). Data is encrypted at rest with AES-256 across databases, storage and backups, and in transit with TLS 1.2 or higher. Stored credentials and API keys carry an extra layer of field-level encryption, and application secrets are never held in source code.
Access follows least privilege with role-based access control, so users only see the data their role and organisation allow. Multi-factor authentication is enforced for every user, enterprise single sign-on is supported, and sessions are invalidated the moment a password or role changes. Every create, update and delete is recorded in a per-customer activity log retained for at least twelve months.
GDPR: fully compliant. ICO registration ZA921150, a named Data Protection Officer, and data processing agreements in every customer contract.
Penetration testing: annual and CREST-accredited. Findings are remediated and independently re-tested.
Sub-processors: documented. Regional processing is configured in the EU or UK where possible, with recognised transfer mechanisms elsewhere.
Every code change is reviewed before it reaches a protected branch and is deployed through automated pipelines. Static analysis, secret scanning with push protection, and dependency and supply-chain monitoring run across all repositories. The platform undergoes annual penetration testing by a CREST-accredited firm, and findings are remediated and independently re-tested.
Databases are backed up continuously with point-in-time recovery, plus hourly and daily snapshots stored encrypted across multiple cloud regions. Restores are tested at least quarterly and a full disaster recovery exercise runs every year. The entire infrastructure is defined as code, so the environment can be rebuilt in a fresh region if one ever fails.
Administrative actions across our cloud accounts are audit-logged with long-term retention, application logs are centralised with alerting, and an on-call engineer responds to alerts at all times. Incidents are managed under a defined response plan covering detection, containment, recovery and post-incident review, with breach notification in line with UK GDPR.
We do not sell personal data and we never use customer content for advertising. Your data is not used to train AI models unless you explicitly opt in, and document extraction runs through APIs whose data is not used for training. Our Data Processing Addendum sets out these commitments, together with our current sub-processor list.
If you discover a security vulnerability, please contact security@etainabl.com. We aim to respond within 48 hours.
Quick answers on where your data lives, who can see it and how it is protected.
On AWS, with the primary region in the EU (Ireland). Our database service runs on AWS in the same region, and we configure regional processing in the EU or UK wherever a provider supports it.
Yes. Data is encrypted at rest with AES-256 across databases, object storage and backups, and in transit with TLS 1.2 or higher. Stored credentials and API keys are additionally encrypted at field level.
Only the users your organisation authorises, scoped by role-based access control, with multi-factor authentication enforced for everyone. Etainabl staff access is limited by least privilege with short-lived credentials, and every significant action is recorded in an activity log kept for at least twelve months.
No, not unless you explicitly opt in. Document extraction runs through APIs whose data is not used for model training, and we never sell personal data or use customer content for advertising.
A CREST-accredited firm carries out penetration testing every year, and findings are remediated and independently re-tested. Alongside that, static analysis, secret scanning and dependency monitoring run continuously, backup restores are tested at least quarterly, and a full disaster recovery exercise runs annually.
Yes. Etainabl is registered with the ICO (registration ZA921150), has a named Data Protection Officer, and includes a Data Processing Addendum in customer agreements covering security, sub-processors and international transfers.
Email security@etainabl.com. We aim to respond within 48 hours.
Our team is happy to walk through our security practices, hosting, and compliance roadmap.
Get in touch