Security is built into every processor and workflow.
Storage & encryption
- Files are encrypted at rest with AES-256 and in transit via TLS 1.2+.
- Processing occurs in the eu-west-1 region by default; contact support to enable additional regions.
- Access is scoped to your workspace; every API key maps to a least-privilege role.
Retention controls
- Default retention is 30 days for uploads and run outputs.
- Override in https://app.algorythmos.fr/settings/security to shorten or extend retention (1–90 days).
- Enable Auto-delete on success for sensitive documents and we purge outputs immediately after webhook delivery.
GDPR & compliance
- Algorythmos acts as a data processor under GDPR; review the DPA in Settings → Legal.
- Request data exports or deletion at any time by emailing dpo@algorythmos.fr with your workspace slug.
- Audit trails and access logs are available to workspace admins.
Operational best practices
- Rotate API keys quarterly.
- Use dedicated service accounts for server-to-server calls.
- Monitor suspicious activity in Console → Settings → Security → Activity Logs.