🛡️ Sovereign · EU-hosted · Self-host ready
Trust & Compliance
Security posture · Data residency · Audit
Argonix is built for European enterprises that need clear answers to security, data-residency and compliance questions — without lawyers translating marketing copy. This page lists what is true, in production, today.
Compliance Posture
Honest status — what we map to, what we are audited against, what is in progress.
SOC 2 Type II
In progressControls implemented across security, availability and confidentiality. Type II audit window open with an EU-recognised auditor.
ISO 27001
In progressISMS scoped, risk register, statement of applicability and Annex A controls in place. Certification audit on schedule.
GDPR
CompliantEU-based controller and processor. DPA available on request. Records of processing, sub-processor list and DSR workflow in place.
NIS2
AlignedBuilt-in detection rules, audit log, incident timeline and 24h reporting workflow — directly aligned with NIS2 obligations.
EU AI Act
TransparentDocumented model providers, prompt logging, opt-out from training, EU-hosted inference options (Mistral, Llama on EU GPUs).
CIS / MITRE
MappedEvery CSPM finding maps to CIS Benchmarks (AWS, GCP, Azure, K8s) and detection rules map to MITRE ATT&CK tactics and techniques.
Data Residency & Sovereignty
Your data stays where you decide. No US fallback, no transparent re-routing.
🇪🇺 Argonix Cloud (EU)
- • Primary region: Frankfurt (Hetzner / EU-owned providers)
- • France region available on request
- • Database, object storage, queue, vector index — all in the same region
- • No data leaves the EU, ever
- • EU-based legal entity (France)
🏠 Self-hosted
- • Helm chart + Kubernetes Operator (22 CRDs)
- • Air-gapped install supported
- • Bring your own LLM endpoint (vLLM, Ollama, Bedrock, Mistral)
- • Bring your own object store, Postgres, Redis
- • Source available license — see GitHub
Security Controls
🔐 Encryption
TLS 1.3 in transit. AES-256 at rest. Secrets encrypted with envelope encryption (cloud KMS or Vault).
🪪 SSO & MFA
Google, GitHub, Microsoft, generic OIDC and SAML 2.0. TOTP MFA on the native account. Per-organisation enforcement.
👥 RBAC
Multi-tenant by design. 4 organisation roles (owner, admin, editor, viewer). Per-resource permissions enforced server-side.
📜 Immutable Audit Log
Every privileged action recorded with actor, IP, resource, before/after. Append-only, exportable to SIEM, retained 13 months by default.
🔑 Scoped API tokens
Per-organisation, per-scope tokens. Expiry, revocation, last-used tracking. No long-lived shared credentials.
🧪 Pentest & SAST
Annual third-party penetration test. SAST, dependency scanning, container scanning, secret scanning on every PR. Daily SCA on production images.
Sub-processors
Short list, EU-first. Updated when it changes.
| Vendor | Purpose | Region | Data |
|---|---|---|---|
| Hetzner | Compute, database, object storage | 🇩🇪 Frankfurt | All customer data |
| Stripe | Billing & payments | 🇮🇪 Ireland | Email, billing address, VAT |
| Brevo | Transactional email | 🇫🇷 France | Email, name |
| Mistral / OpenAI / Anthropic | LLM inference (configurable, opt-out) | 🇪🇺 EU endpoints when available | Only prompts you explicitly send to Argos |
| Cloudflare | DDoS protection, CDN for static assets | 🇪🇺 EU edge | Public assets only |
Self-hosted customers run with zero Argonix-managed sub-processors.
Incident Response & Disclosure
🚨 Notification SLA
Customers affected by a security incident are notified within 72 hours at most (in line with GDPR and NIS2). High-impact incidents are posted on our public status page within hours.
🐛 Responsible disclosure
Security researchers can report vulnerabilities to security@argonix.io (PGP available). We acknowledge within 48h, fix critical issues within 7 days, and credit researchers in our changelog.
Documents on Request
Email security@argonix.io or your Argonix contact.
FAQ
Where is my data stored?
By default in Frankfurt (Hetzner). A France region is available on request. Self-hosted customers store data wherever they deploy.
Does Argonix train AI on my data?
No. We never train on customer data, prompts or outputs. LLM providers used through our managed offering are configured with training opt-out. Self-hosted customers can wire any local model.
Are you subject to the US CLOUD Act?
No. Argonix is a French entity, with EU-only infrastructure for the managed offering. Our default sub-processor is Hetzner (German). Customers requiring stricter postures can self-host.
Do you have a security questionnaire on file?
Yes — CAIQ Lite and a custom long-form questionnaire are available under NDA. Request via security@argonix.io.
What is your uptime SLA?
99.9% monthly availability on the managed offering for Pro and Enterprise plans, with service credits on breach. Higher SLOs (99.95% / 99.99%) available on Enterprise.
Explore More
Need a Security Review?
We answer security questionnaires in days, not weeks. Book a call or email us directly.