We built Tenor Analytics with privacy at the core — not as an afterthought. Here is exactly how we handle your data.
All data processing follows GDPR regulations. You retain full ownership of your data at all times.
Uploaded files are permanently deleted from our servers the moment your report is generated.
All data is transferred over HTTPS/TLS 1.3. No data is ever sent over unencrypted connections.
All servers and storage are hosted in EU data centres. Your data never leaves European jurisdiction.
We use your data exclusively to generate your report. Full stop.
We deliberately chose enterprise-grade infrastructure partners with strong security track records.
Serverless compute and hosting. SOC 2 Type II certified, GDPR compliant. Isolated execution environments per request.
PostgreSQL database with row-level security. Data encrypted at rest (AES-256). EU region. SOC 2 Type II certified.
Temporary file storage with automatic deletion policies. Files stored in EU, never replicated outside EU jurisdiction.
All payments processed by Stripe. PCI DSS Level 1 certified. We never store card numbers — Stripe handles all payment data.
Transactional email delivery. Reports sent over encrypted SMTP. Email addresses never shared with third parties.
AI analysis via API with zero data retention agreements. Your data is not used to train any AI models per our API agreements.
We take security reports seriously. If you've found a vulnerability or have a privacy concern, please contact us directly. We aim to respond within 24 hours.
Report a vulnerability