TRUST CENTRE
Where your data is, who reaches it, what is recorded
Trusting a cloud provider takes three answers: where the data sits, who can reach it, and whether what happened is recorded. We answer all three here, plainly.
- Data centre: Türkiye
- Role-based access
- Tamper-proof audit trail
Your data stays in Türkiye
Your servers, databases and backups are hosted in our data centre in Türkiye; data is not transferred abroad.
Tenant isolation
Every customer runs in their own isolated project; resources, networks and quotas are separated at the customer boundary.
Role-based access and scoped keys
Assign roles to your team and give your automation narrowly scoped API keys; calls outside a key's scope are rejected.
Two-factor authentication
TOTP-based two-factor authentication can be enabled for accounts and works with standard authenticator apps.
The platform audit trail CANNOT be altered
Actions taken through the panel and the API are written to the audit trail, and a database-level protection prevents those records from being changed or deleted afterwards. Not an application rule: a database rule.
HTTPS and HSTS
The panel and the API are served over HTTPS, and the server sends HSTS so your browser is forced to use HTTPS on subsequent connections.
FAQ
Frequently asked questions
Where is my data held?
In our data centre in Türkiye. See our KVKK & Data Residency page for the detail and the regulatory framing.
Can the audit trail be altered afterwards?
For the platform audit trail, no: updating and deleting records of panel and API actions is blocked at the database level — not an application rule but a constraint that lives in the data itself. Other records produced by the platform's own internal components do not yet carry the same protection.
What happens if an API key leaks?
You revoke it from the panel and revocation is immediate. Because keys can be created with a narrow scope, the surface a leaked key can reach can be kept small.
Can your staff access my data?
Access is role-based and limited to the narrowest permission needed to operate the platform; actions are written to the audit trail.
Do you hold an independent compliance certification?
Tell us your compliance requirements and which documents you need, and we will work through the process with you. We do not list certifications we do not hold on this page.