Security

Your data is safe with us.

We built Tenor Analytics with privacy at the core — not as an afterthought. Here is exactly how we handle your data.

GDPR Compliant

All data processing follows GDPR regulations. You retain full ownership of your data at all times.

Files Deleted Instantly

Uploaded files are permanently deleted from our servers the moment your report is generated.

Encrypted in Transit

All data is transferred over HTTPS/TLS 1.3. No data is ever sent over unencrypted connections.

EU Cloud Infrastructure

All servers and storage are hosted in EU data centres. Your data never leaves European jurisdiction.

Data lifecycle

What happens to your file.

Upload — your file is sent over HTTPS directly to our encrypted temporary storage (Cloudflare R2, EU region).
Processing — our AI reads and analyses your data in an isolated serverless environment. No human ever sees your raw data.
Report generated — your PDF is created and queued for delivery. The raw file is deleted from temporary storage immediately.
Delivery — report sent to your email via Resend. The PDF is stored encrypted in your report history for your plan's retention period.
Retention — reports are kept for 30 days (Starter), 90 days (Growth), or 1 year (Pro/Agency), then permanently deleted.

Your data is never sold, shared, or used to train AI models.

We use your data exclusively to generate your report. Full stop.

Infrastructure

Built on trusted platforms.

We deliberately chose enterprise-grade infrastructure partners with strong security track records.

Vercel

Serverless compute and hosting. SOC 2 Type II certified, GDPR compliant. Isolated execution environments per request.

Supabase

PostgreSQL database with row-level security. Data encrypted at rest (AES-256). EU region. SOC 2 Type II certified.

Cloudflare R2

Temporary file storage with automatic deletion policies. Files stored in EU, never replicated outside EU jurisdiction.

Stripe

All payments processed by Stripe. PCI DSS Level 1 certified. We never store card numbers — Stripe handles all payment data.

Resend

Transactional email delivery. Reports sent over encrypted SMTP. Email addresses never shared with third parties.

Anthropic / OpenAI

AI analysis via API with zero data retention agreements. Your data is not used to train any AI models per our API agreements.

Security contact

Found a vulnerability?

We take security reports seriously. If you've found a vulnerability or have a privacy concern, please contact us directly. We aim to respond within 24 hours.

Report a vulnerability