EU-hosted · GDPR-compliant
Security you can audit, not just trust.
OneHazel is Malta-based, EU-hosted, and GDPR-compliant. Here's exactly how we protect your data.
Data Architecture
Encryption
AES-256-GCM tenant isolation. All data encrypted at rest and in transit via TLS 1.2+.
Data Residency
All data hosted on EU infrastructure. No cross-border transfers. Data stays in the EU at all times.
Tenant Isolation
Complete per-tenant data separation at the storage layer. Your data is never co-mingled with another customer's data.
Incident Response
99.9% uptime target
Incidents are disclosed to affected customers within 24 hours. Platform status available at onehazel.com/status.
Security contact
security@onehazel.comResponse SLAs
Critical vulnerability report< 4 hours
Security inquiry< 24 hours
Incident notification to customers< 24 hours
GDPR Data Processing Agreement
OneHazel acts as a Data Processor for your operator data. You remain the Data Controller. We process data solely for the purposes of delivering the OneHazel platform services as described in your agreement. Our DPA covers:
Sub-processor disclosures
Data subject rights procedures
Breach notification obligations
International transfer safeguards
Retention and deletion policies
Security measures documentation