2026-08-07 — marketing/trust-page copy, aligned with DPA Annex 2. Every claim below must be true before publication.
Security posture. Blunox is built for security-conscious data teams. Customer data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Production access is role-based, least-privilege, MFA-protected, and logged. RBAC scopes (account · project · environment) from day one.
Hosting & data residency. Blunox runs on Google Cloud with customer-selectable hosting regions: United States and Belgium (europe-west1). Your data at rest stays in the region you choose. On the Enterprise plan, self-hosted runners keep data entirely within your own VPC — pushdown execution means warehouse data is processed in place (BigQuery, Databricks, Redshift) and never copied out.
Compliance. SOC 2 Type II and ISO 27001 are on our security roadmap ahead of general availability. GDPR and UAE PDPL aligned; DPA with EU Standard Contractual Clauses available to all customers at blunox.ai/legal/dpa.
AI you can trust. Mira's agents operate with a human approving every change, and we never train AI models on your data. Details: blunox.ai/legal/ai-addendum.
Reliability. Availability targets, service credits, and support response times for Enterprise plans are defined in our Service Level Agreement (blunox.ai/legal/sla); a public status page is coming soon. Pulse delivers exactly-once, checkpointed replication designed to resume cleanly from failure.
Practices. Independent penetration testing annually; vulnerability disclosure via security@blunox.ai (see /.well-known/security.txt); documented incident response with prompt customer notification; staff under confidentiality obligations; vendor due diligence and DPAs for all subprocessors.
Documents available on request (under NDA where needed): penetration test summary, security questionnaire (CAIQ/SIG) responses, architecture overview.
Questions about this document can be sent to legal@blunox.ai.