Skip to content

Trust Center

Everything a procurement or security team needs to evaluate EM3A. Maintained by ShiftNode Digital s.r.o.. Last updated August 9, 2026 · v2.2.0.

Editable content notice. This page is maintained by ShiftNode Digital s.r.o. to answer common security and privacy questions about EM3A. It is not an independent attestation. ShiftNode Digital s.r.o. does not currently hold SOC 2 Type II or ISO/IEC 27001 certification; the controls described below reflect operational practices modelled on those frameworks. Signed agreements (MSA, DPA, SLA) control over this public copy.

Request a signed DPA

Email legal@em3a.ai — we counter-sign within 3 business days.

Email legal

Read the full DPA

GDPR Art. 28, SCCs (Modules 2 & 3), UK IDTA Addendum included.

Open DPA

Report a vulnerability

Coordinated disclosure — 90-day window before publication.

Email security

Shipped controls

Tenant isolation

Row-Level Security on every tenant table; server-side enforcement via SECURITY DEFINER helpers scoped to org_id.

Authentication & MFA

Email/password + Google OAuth. Optional TOTP MFA with backup codes; per-org MFA enforcement policy with grace window and hard gate on sensitive routes.

Session hardening

30-minute idle timeout, 12-hour absolute session ceiling, per-user 'Sign out from all devices' revoking every refresh token.

Tamper-evident audit logs

SHA-256 hash-chained rows in user_activity_audit, admin_audit_log, and org_audit_log. verify_audit_chain() RPC detects any insert, edit, or reorder.

SIEM export (Enterprise)

Signed webhooks fan out audit events every 5 minutes to Enterprise-entitled subscribers (audit.user_activity / .admin_action / .org_event).

Retention & 30-day deletion

Daily purge of operational logs (90d/180d windows). User-initiated account deletion is queued and hard-deleted after 30 days by an hourly worker.

Companion documents

Pre-answered security questionnaire

SIG-Lite / CAIQ-Lite shape

Covers the questions we most often see in mid-market and SME vendor reviews. Need the full SIG or CAIQ workbook? Email security@em3a.ai.

Governance & Compliance

Access control & identity

Data protection

Application & AI security

Operations & incident response

Talk to a human

Procurement / DPA
legal@em3a.ai