Trust Center

Where your data lives, and how it's protected.

Everything is auditable and explained — data residency, security controls, and the sub-processors we rely on.

Posture

Auditable by design

Data residency

All Remitto data is stored and processed in EU regions — Postgres (eu-central-1), object storage in an EU bucket, workflow orchestration in EU, and EU compute regions. Your data never leaves the EU.

GDPR

Remitto is GDPR-native: clear lawful bases for processing, data minimization by design, and a documented processing register. A Data Processing Agreement is available to customers (final language pending legal review).

Security

TLS 1.3 in transit and AES-256 at rest. Carrier credentials are encrypted and access-scoped per organization. Access is role-based with least-privilege defaults, and privileged actions are written to an immutable audit log.

Responsible disclosure

Security researchers can report vulnerabilities to security@remitto.io. We operate a 90-day coordinated disclosure policy.

Sub-processors

Who processes your data

Each operates under a data processing agreement; all process data in the EU. We notify customers of material changes to this list.

Sub-processorPurposeLocationDPA
WorkOS Authentication & SSO EU On file
Stripe Billing & payments EU On file
Neon Postgres database EU (eu-central-1) On file
Temporal Cloud Workflow orchestration EU On file
Resend Transactional email EU On file
Cloudflare R2 Object storage EU On file
Upstash Cache / Redis EU On file
Axiom Logging EU On file
Sentry Error monitoring EU On file

Questions: privacy@remitto.io.

Security your auditors
can verify.

Connect a carrier and see the audit trail for yourself. EU-resident, GDPR-native, free to start.