TRUST & SECURITY
Built to be trusted with data.
Kontor handles company and business-contact data for a living, so the way we protect it is part of the product, not an afterthought. This page is the short version; a security team can go deeper via the documents linked at the bottom.
DATA HANDLING
EU data residency
All primary data — database, authentication, file storage — is hosted in the EU (AWS eu-west-1, Ireland). We are a German company and keep data in Europe.
Encryption
TLS in transit everywhere; AES-256 at rest via our infrastructure providers.
Tenant isolation
Enforced at the database layer with Postgres row-level security scoped to your organization — not just in application code.
No passwords stored
Sign-in is passwordless (magic link). There is no password database to breach.
PRIVACY · GDPR-NATIVE
Data minimization
Personal contact data is created on demand when you reveal a contact — never bulk harvested speculatively.
Provenance on every record
Each personal datum carries its source, method, and verification date, shown to every user who sees it.
Immediate, free objection
Anyone can remove their data with no account and no payment. Suppression is checked at enrichment, reveal, and export.
No sending, ever
Kontor never sends email to the people in its database. We are a source, not a sender — so the deliverability and consent liability of outbound stays with the tools you already use.
SUBPROCESSORS
| Provider | Purpose | Location |
|---|---|---|
| Supabase (AWS eu-west-1) | Database, auth, storage | EU · Ireland |
| Vercel | Web app hosting | Global edge |
| Railway | Pipeline hosting | EU region |
| Anthropic | LLM classification (public text only) | US · SCCs |
| Prospeo / Anymailfinder | Contact finding (on reveal) | EU/US · SCCs |
| MillionVerifier | Email verification (on reveal) | EU |
CERTIFICATIONS · HONEST STATUS
We don't claim what we don't hold. Kontor is not yet SOC 2 or ISO 27001 certified — those are on the roadmap as European mid-market demand warrants (ISO 27001 first). The technical controls those audits examine — EU residency, row-level isolation, encryption, secret management, dependency pinning with a CI-generated software bill of materials — are in place today, and we'll share our security overview and (when complete) penetration-test summary under NDA.
REPORT A VULNERABILITY
Email security@durn.io. We acknowledge within 3 business days. See our security.txt.