Keamanan
EU-hosted. EU-licensed. EU-rules.
Tiga lapisan kepercayaan, semua dirancang untuk realitas bisnis Eropa.
Uang: escrow berlisensi PSD2
Dana Jaminan Perdagangan disimpan di bawah lisensi lembaga uang elektronik Mangopay, diatur oleh Komisi Pengawasan Sektor Keuangan di Luksemburg, berlisensi EU. Dana disimpan di akun klien terpisah di bank mitra kami, bukan di neraca listing.company — yang berarti bahkan jika listing.company sebagai perusahaan mengalami masa sulit, dana Anda yang disimpan aman dari kebangkrutan dan dapat dipulihkan.
Pembayaran kartu diproses melalui Stripe (disertifikasi PCI-DSS Level 1, tingkat tertinggi). listing.company tidak pernah melihat nomor kartu lengkap — mereka ditokenisasi di Stripe dan hanya token yang disimpan.
Data: EU-only, GDPR-native
Servers in Hetzner Falkenstein (Germany) and Helsinki (Finland). No data leaves the EU. No data is sent to a US-based AI provider — every model that processes user content runs on listing.company-owned GPUs in those same EU data centers. The implication: a European business using listing.company never has to worry about US CLOUD Act exposure or non-EU subprocessor risk.
You can export everything we have on you in machine-readable JSON in one click (GDPR Article 15). You can delete it just as easily (Article 17). Audit log of who-touched-what for the last 24 months on every claimed listing.
Communications: encrypted end-to-end
Inquiry messages, AI translations, dispute discussions — all encrypted at rest with rotating per-tenant keys. In transit, TLS 1.3 only (no fallback to weaker ciphers). The AI translator processes content in-memory only; we don't train any model on user content.
Account access
Email + password (bcrypt-hashed, 12-round work factor) + optional TOTP 2FA via any standard authenticator app. SSO via SAML/OIDC available for Enterprise tier. Session cookies are HTTP-only, Secure, SameSite=Lax.
Compliance status
- GDPR-ready since launch
- EU AI Act — risk-classified as Limited Risk for our agent-stack
- Mangopay license assignment in progress, scope: e-money issuance for marketplace
- SOC 2 Type II — audit scheduled Q4 2026
- ISO 27001 — gap analysis complete, certification cycle Q1 2027
Have a security question?
Coordinated disclosure or audit request? We respond within 48 hours.
security@blun.ai
