TRUST & SECURITY

Built to be trusted with data.

Kontor handles company and business-contact data for a living, so the way we protect it is part of the product, not an afterthought. This page is the short version; a security team can go deeper via the documents linked at the bottom.

DATA HANDLING

EU data residency

All primary data — database, authentication, file storage — is hosted in the EU (AWS eu-west-1, Ireland). We are a German company and keep data in Europe.

Encryption

TLS in transit everywhere; AES-256 at rest via our infrastructure providers.

Tenant isolation

Enforced at the database layer with Postgres row-level security scoped to your organization — not just in application code.

No passwords stored

Sign-in is passwordless (magic link). There is no password database to breach.

PRIVACY · GDPR-NATIVE

Data minimization

Personal contact data is created on demand when you reveal a contact — never bulk harvested speculatively.

Provenance on every record

Each personal datum carries its source, method, and verification date, shown to every user who sees it.

Immediate, free objection

Anyone can remove their data with no account and no payment. Suppression is checked at enrichment, reveal, and export.

No sending, ever

Kontor never sends email to the people in its database. We are a source, not a sender — so the deliverability and consent liability of outbound stays with the tools you already use.

SUBPROCESSORS

ProviderPurposeLocation
Supabase (AWS eu-west-1)Database, auth, storageEU · Ireland
VercelWeb app hostingGlobal edge
RailwayPipeline hostingEU region
AnthropicLLM classification (public text only)US · SCCs
Prospeo / AnymailfinderContact finding (on reveal)EU/US · SCCs
MillionVerifierEmail verification (on reveal)EU

CERTIFICATIONS · HONEST STATUS

We don't claim what we don't hold. Kontor is not yet SOC 2 or ISO 27001 certified — those are on the roadmap as European mid-market demand warrants (ISO 27001 first). The technical controls those audits examine — EU residency, row-level isolation, encryption, secret management, dependency pinning with a CI-generated software bill of materials — are in place today, and we'll share our security overview and (when complete) penetration-test summary under NDA.

REPORT A VULNERABILITY

Email security@durn.io. We acknowledge within 3 business days. See our security.txt.