---
title: "Security & Compliance | Hosting in France, GDPR, 99.9% SLA - Natalia"
description: "Natalia security: hosting in France, GDPR by design, DPA art. 28, TLS 1.2+, 99.9% SLA. Your data is never used to train our models."
url: https://getnatalia.com/en/security
lang: en
---

  

Security & compliance

# Your data security, by design

France hosting, GDPR compliance, guaranteed uptime and audited security controls. What your IT teams, CISOs and RFPs expect.

✅ France hosting ✅ GDPR by design ✅ DPA art. 28 ✅ TLS 1.2+ ✅ Data not used for training ✅ 72h breach notification ✅ Immutable audit log ✅ Annual pen test ⏳ ISO 27001 in progress ⏳ SOC 2 controls

In placeRoadmap

## Data protection

Your data is never used to train our models, nor our technology partners' models.

-   ### Hosted in France

    Your data is hosted in France, within the European Union.

-   ### GDPR-compliant by design

    Data protection is built into every step, not bolted on afterwards.

-   ### DPA (art. 28) available

    A data processing agreement governs our processor role, on request.

## Availability

99.9% guaranteed uptime, contractual SLA (see our [Terms](https://getnatalia.com/en/terms-of-service)).

Our uptime commitment is contractual: calculation method, maintenance exclusions and terms are set out in our conditions.

## Compliance & certifications

Our information security management system (ISMS) is built to align with ISO 27001 requirements and incorporates SOC 2 controls. ISO 27001 certification in progress.

Security governance relies on strict access controls, an annual third-party penetration test, and notification of any data breach within 72 hours.

## Security controls

The technical and organizational measures that protect your conversations every day.

-   ### Encryption in transit

    All communications are encrypted using TLS 1.2 or higher.

-   ### Immutable audit log

    Sensitive access and actions are recorded in a tamper-proof log.

-   ### 72-hour notification

    In the event of a data breach, notification within the regulatory 72-hour window.

-   ### Annual penetration test

    An independent provider runs a penetration test every year.

-   ### Access control

    Multi-factor authentication and least-privilege access.

-   ### Data not used for training

    Your data never feeds the training of our models or our partners' models.

The selection, organization and presentation of the information contained in this documentation constitute a proprietary asset of Natalia. Internal implementation details (software versions, specific cloud providers, proprietary algorithms, data schemas) are not disclosed in this document. Additional details required for CISO / RFP audits are available on request under a non-disclosure agreement. Contact [security@getnatalia.com](mailto:security@getnatalia.com).

Evaluating cloud sovereignty standards (SecNumCloud, SEAL, CLOUD Act)? Read the [sovereign cloud guide](https://getnatalia.com/en/sovereignty/sovereign-cloud-guide).

## A CISO audit or RFP in progress?

We provide the additional materials under a confidentiality agreement.

[Contact the security team](https://getnatalia.com/en/contact)
