EU-hosted · GDPR-compliant

Security you can audit, not just trust.

OneHazel is Malta-based, EU-hosted, and GDPR-compliant. Here's exactly how we protect your data.

Data Architecture

Encryption

AES-256-GCM tenant isolation. All data encrypted at rest and in transit via TLS 1.2+.

Data Residency

All data hosted on EU infrastructure. No cross-border transfers. Data stays in the EU at all times.

Tenant Isolation

Complete per-tenant data separation at the storage layer. Your data is never co-mingled with another customer's data.

Incident Response

99.9% uptime target

Incidents are disclosed to affected customers within 24 hours. Platform status available at onehazel.com/status.

Security contact
[email protected]

Response SLAs

Critical vulnerability report < 4 hours
Security inquiry < 24 hours
Incident notification to customers < 24 hours

GDPR Data Processing Agreement

OneHazel acts as a Data Processor for your operator data. You remain the Data Controller. We process data solely for the purposes of delivering the OneHazel platform services as described in your agreement. Our DPA covers:

Sub-processor disclosures
Data subject rights procedures
Breach notification obligations
International transfer safeguards
Retention and deletion policies
Security measures documentation
Request DPA