Security & Compliance
Last updated: 14 September 2026
This page answers what a security or procurement review usually asks, plainly, including where there isn't yet an answer to give.
Jurisdiction
Vault42 will be incorporated and hosted entirely within the European Union, with no US infrastructure and no US parent company. As a result, it is not subject to the US CLOUD Act or similar extraterritorial legal demands.
Two US laws are usually raised in procurement reviews. The CLOUD Act lets US law enforcement require a US provider to disclose data it holds, wherever that data is stored. Section 702 of the Foreign Intelligence Surveillance Act (FISA) lets US intelligence agencies require the same providers to assist with surveillance of non-US persons, without an individual warrant and without notifying the customer. Both apply because of who controls the provider, wherever the servers are located. Vault42 will have no US entity and no US infrastructure, so neither law gives a US authority a way to compel it to hand over your data.
Infrastructure
Vault42 runs on Scaleway, a European infrastructure provider, across data centres in Paris, Amsterdam, Warsaw and Milan. Servers are owned, operated and governed entirely within the EU; nothing is routed through a US cloud.
Backups and recovery
Backups run daily and are kept for 30 days. Every backup is replicated to a second EU region, and the restore procedure is documented and tested regularly, not only written down.
Data protection
A Data Processing Agreement is available on request, and we publish a sub-processor list.
Certifications
Vault42 holds no third-party security certifications at this time, such as ISO 27001 or SOC 2. This page will be updated if that changes.
Data protection officer
Vault42 does not currently process data at a scale or of a kind that requires a Data Protection Officer under GDPR Article 37. For data protection questions, contact privacy@vault42.eu directly.
Contact
Email privacy@vault42.eu.