Skip to main content
Abundly is built on enterprise-grade cloud infrastructure with security and compliance at its foundation. All data is stored in EU data centers, encrypted at rest and in transit, and protected by comprehensive access controls. This page provides the technical details enterprise security teams need.

Data residency

All customer data is stored in EU data centers, specifically in Stockholm, Sweden:
ComponentLocation
DatabaseAWS eu-north-1 (Stockholm)
Agent ServiceGCP europe-north2 (Stockholm)
File StorageGCP europe-north2 (Stockholm)
Task QueueGCP europe-north2 (Stockholm)
EU data residency ensures compliance with GDPR and other European data protection regulations. Data does not leave the EU.

Encryption

TypeStandard
At restAES-256 encryption for all stored data
In transitTLS 1.2+ / HTTPS for all communication
SecretsRSA-OAEP with SHA-256 (see Credentials)
All communication between components is encrypted. HTTPS is enforced for all endpoints.

Compliance status

StandardStatusNotes
GDPRCompliantEU data residency in Stockholm
Data EncryptionMetAES-256 at rest, TLS 1.2+ in transit
Access ControlsComprehensiveRole-based permissions
SOC 2 Type IIPlannedCertification in progress
ISO 27001EvaluationUnder consideration

Audit trails

Every agent action is logged with complete context:
FieldDescription
TimestampWhen the action occurred
ActorWhich agent performed the action
TriggerWhat initiated the action (email, schedule, chat, etc.)
PlanWhat the agent intended to do
ExecutionWhat tools were called and what happened
ResultThe outcome of the action
Audit logs are immutable and cannot be modified or deleted after creation.
You can access audit information through:
  • Activity log — Real-time and historical view of agent actions with full details
  • Agent diary — High-level summary of what each agent has been doing
See Activity Monitoring for details on using these tools.

Data retention

Data TypeRetention
Account InformationWhile account active; deleted within 30 days of account deletion
User ContentRetained to provide services; deleted within 30 days after deletion
Log DataUp to 90 days for security and troubleshooting
Usage DataAnonymized data may be retained for analytics
BackupsData may remain in backups up to 9 months

System architecture

The platform is built on cloud-native infrastructure:
ComponentTechnologyLocation
Web PortalVercel, Next.js/ReactVercel Edge Network
Agent ServiceGoogle Cloud Run, Node.jsGCP europe-north2
DatabaseMongoDB AtlasAWS eu-north-1
Task QueueGoogle Cloud TasksGCP europe-north2
File StorageGoogle Cloud StorageGCP europe-north2

Availability and disaster recovery

FeatureImplementation
Cloud-native resilienceAutomatic failover via Vercel and GCP
Automated backupsDaily with point-in-time recovery
Backup retention9 months with cross-region replication
Health monitoringContinuous monitoring with alerting
RTO (Recovery Time)24 hours for critical services
We maintain a documented Disaster Recovery Plan covering database recovery, secrets restoration, and service continuity.

Security monitoring

ActivityApproach
Infrastructure monitoringAutomated via GCP, MongoDB Atlas, Vercel
Alert configurationEmail notifications to technical team
Active monitoringDaily dashboard review
Incident responseCritical alerts within 1 hour (business hours)
Penetration testingAnnual third-party testing

Enterprise compliance

For enterprise customers, we can provide:
  • Custom data retention policies
  • Dedicated compliance documentation
  • Audit support and reports
  • Custom DPA terms

Contact Us

Need custom compliance arrangements? Contact our team.