Argonix

🛡️ Sovereign · EU-hosted · Self-host ready

Trust & Compliance
Security posture · Data residency · Audit

Argonix is built for European enterprises that need clear answers to security, data-residency and compliance questions — without lawyers translating marketing copy. This page lists what is true, in production, today.

Compliance Posture

Honest status — what we map to, what we are audited against, what is in progress.

SOC 2 Type II

In progress

Controls implemented across security, availability and confidentiality. Type II audit window open with an EU-recognised auditor.

ISO 27001

In progress

ISMS scoped, risk register, statement of applicability and Annex A controls in place. Certification audit on schedule.

GDPR

Compliant

EU-based controller and processor. DPA available on request. Records of processing, sub-processor list and DSR workflow in place.

NIS2

Aligned

Built-in detection rules, audit log, incident timeline and 24h reporting workflow — directly aligned with NIS2 obligations.

EU AI Act

Transparent

Documented model providers, prompt logging, opt-out from training, EU-hosted inference options (Mistral, Llama on EU GPUs).

CIS / MITRE

Mapped

Every CSPM finding maps to CIS Benchmarks (AWS, GCP, Azure, K8s) and detection rules map to MITRE ATT&CK tactics and techniques.

Data Residency & Sovereignty

Your data stays where you decide. No US fallback, no transparent re-routing.

🇪🇺 Argonix Cloud (EU)

  • • Primary region: Frankfurt (Hetzner / EU-owned providers)
  • • France region available on request
  • • Database, object storage, queue, vector index — all in the same region
  • • No data leaves the EU, ever
  • • EU-based legal entity (France)

🏠 Self-hosted

  • • Helm chart + Kubernetes Operator (22 CRDs)
  • • Air-gapped install supported
  • • Bring your own LLM endpoint (vLLM, Ollama, Bedrock, Mistral)
  • • Bring your own object store, Postgres, Redis
  • • Source available license — see GitHub

Security Controls

🔐 Encryption

TLS 1.3 in transit. AES-256 at rest. Secrets encrypted with envelope encryption (cloud KMS or Vault).

🪪 SSO & MFA

Google, GitHub, Microsoft, generic OIDC and SAML 2.0. TOTP MFA on the native account. Per-organisation enforcement.

👥 RBAC

Multi-tenant by design. 4 organisation roles (owner, admin, editor, viewer). Per-resource permissions enforced server-side.

📜 Immutable Audit Log

Every privileged action recorded with actor, IP, resource, before/after. Append-only, exportable to SIEM, retained 13 months by default.

🔑 Scoped API tokens

Per-organisation, per-scope tokens. Expiry, revocation, last-used tracking. No long-lived shared credentials.

🧪 Pentest & SAST

Annual third-party penetration test. SAST, dependency scanning, container scanning, secret scanning on every PR. Daily SCA on production images.

Sub-processors

Short list, EU-first. Updated when it changes.

VendorPurposeRegionData
HetznerCompute, database, object storage🇩🇪 FrankfurtAll customer data
StripeBilling & payments🇮🇪 IrelandEmail, billing address, VAT
BrevoTransactional email🇫🇷 FranceEmail, name
Mistral / OpenAI / AnthropicLLM inference (configurable, opt-out)🇪🇺 EU endpoints when availableOnly prompts you explicitly send to Argos
CloudflareDDoS protection, CDN for static assets🇪🇺 EU edgePublic assets only

Self-hosted customers run with zero Argonix-managed sub-processors.

Incident Response & Disclosure

🚨 Notification SLA

Customers affected by a security incident are notified within 72 hours at most (in line with GDPR and NIS2). High-impact incidents are posted on our public status page within hours.

🐛 Responsible disclosure

Security researchers can report vulnerabilities to security@argonix.io (PGP available). We acknowledge within 48h, fix critical issues within 7 days, and credit researchers in our changelog.

Documents on Request

Email security@argonix.io or your Argonix contact.

📄 Data Processing Agreement (DPA)
📄 Standard Contractual Clauses (SCC)
📄 Security whitepaper
📄 Latest pentest summary
📄 SOC 2 / ISO 27001 progress letter
📄 CAIQ (Lite) questionnaire

FAQ

Where is my data stored?

By default in Frankfurt (Hetzner). A France region is available on request. Self-hosted customers store data wherever they deploy.

Does Argonix train AI on my data?

No. We never train on customer data, prompts or outputs. LLM providers used through our managed offering are configured with training opt-out. Self-hosted customers can wire any local model.

Are you subject to the US CLOUD Act?

No. Argonix is a French entity, with EU-only infrastructure for the managed offering. Our default sub-processor is Hetzner (German). Customers requiring stricter postures can self-host.

Do you have a security questionnaire on file?

Yes — CAIQ Lite and a custom long-form questionnaire are available under NDA. Request via security@argonix.io.

What is your uptime SLA?

99.9% monthly availability on the managed offering for Pro and Enterprise plans, with service credits on breach. Higher SLOs (99.95% / 99.99%) available on Enterprise.

Explore More

Need a Security Review?

We answer security questionnaires in days, not weeks. Book a call or email us directly.