GDPR-native is the first sentence, not the footnote.

Remitto handles your carrier data and credentials. Everything is encrypted, EU-resident, access-scoped, and auditable — by design.

Posture

Built to move money, held to the standard that demands

Data residency

  • All data stored in EU regions — database, object storage, and workflow orchestration.
  • Your data never leaves the EU.
  • Single-tenant isolation per organization, enforced at the data layer.

Encryption

  • TLS 1.3 for all data in transit.
  • AES-256 for data at rest.
  • Carrier credentials encrypted and access-scoped per organization.

Access & accountability

  • Role-based access control with least-privilege defaults.
  • Every privileged action is written to an immutable audit log.
  • SSO via your identity provider on higher tiers.

Compliance

  • GDPR-native: clear lawful bases, data minimization, documented processing register.
  • Responsible disclosure: security@remitto.io, 90-day policy.

Reporting a vulnerability? Email security@remitto.io.

Security your auditors
can verify.

Connect a carrier and see the audit trail for yourself. EU-resident, GDPR-native, free to start.