Compliance & Trust

Operated to the standards we sell.

Transtar builds compliance infrastructure for regulated European markets. We hold ourselves to the same bar: EU jurisdiction, EU data residency, and an honest, verifiable compliance posture.

Our posture

Sovereign by design.

What is in place today, stated plainly. Where something is on our roadmap, we say so — with a date, not a badge.

EU jurisdictionActive
All customer contracts are governed under EU law. Transtar Networks Oy is a Finnish entity (Y-tunnus 3407638-8) headquartered in Helsinki.
EU data residencyActive
All customer workloads remain within EU regions. No personal data is transferred outside the EU. Committed contractually in every agreement.
GDPR Article 28 DPAAvailable
A Data Processing Agreement is included by default across all customer tiers, available for review and signature before onboarding.
EU AI Act — Article 53Documented
Article 53 transparency documentation for general-purpose AI use is mapped and provided on request. Posture verifiable on demand.
ISO 27001In progress · Q4 2026
Our Information Security Management System is being established toward ISO 27001 certification, targeted for Q4 2026. Not yet certified.
SOC 2Planned
SOC 2 Type II is on our roadmap, to be initiated on customer demand. Not yet in audit.
We do not present our infrastructure providers' certifications as our own. Where a control is provided by an underlying platform, it is attributed to that provider below.
Data residency

Your data stays in the EU.

Customer personal data and workloads are processed exclusively in EU regions. There are no transfers to third countries in our standard deployment.

NetherlandsPrimary processing regioneurope-west4 · Eemshaven
BelgiumActive regioneurope-west1 · St. Ghislain
GermanyActive regioneurope-west3 · Frankfurt
SwedenActive regionsweden-central · Gävle
Where a customer requires in-country residency (for example, a specific member-state requirement), Transtar can deploy to the corresponding EU region on request. International transfers, if ever required by a customer, are governed by Standard Contractual Clauses and a Transfer Impact Assessment.
Subprocessors

Who processes data on our behalf.

Transtar engages a limited set of vetted subprocessors. Each is bound by a data processing agreement and operates within EU regions for customer data.

Google CloudCompute, vector index, model inferenceEU regions · SOC 2 / ISO 27001 certified
Microsoft AzureCompute, key management (HSM)EU regions · SOC 2 / ISO 27001 certified
Amazon Web ServicesCompute, managed model inference (Bedrock)EU regions · SOC 2 / ISO 27001 certified
This list reflects Transtar's current subprocessors and must be kept current. Customers are notified of material changes to the subprocessor list in advance, per the DPA. Certifications shown are held by the named provider, not by Transtar.
Regulatory coverage

Mapped to 18 EU regulations.

Transtar's platform is built against the EU regulatory frameworks that govern our customers — financial services, data, and risk.

Financial services 12 frameworks
MiCACrypto-assets
Markets in Crypto-Assets Regulation
DORAResilience
Digital Operational Resilience Act
PSD3Payments
Payment Services Directive 3
FIDAOpen finance
Financial Data Access Regulation
MiFID IIMarkets
Markets in Financial Instruments Directive II
MARMarkets
Market Abuse Regulation
EMIRMarkets
European Market Infrastructure Regulation
CSDRMarkets
Central Securities Depositories Regulation
BMRMarkets
Benchmarks Regulation
SFDRDisclosure
Sustainable Finance Disclosure Regulation
CRR/CRDCapital
Capital Requirements Regulation & Directive
IFRCapital
Investment Firms Regulation
Data & risk 6 frameworks
GDPRData
General Data Protection Regulation
AMLFin. crime
Anti-Money Laundering (AMLR / AMLD)
NIS2Cyber
Network & Information Security Directive 2
CRACyber
Cyber Resilience Act
eIDASIdentity
Electronic Identification & Trust Services
EUDIIdentity
EU Digital Identity Wallet (eIDAS 2.0)
Security practices

How we protect data.

Encryption
Data encrypted in transit (TLS 1.2+) and at rest. Key management via FIPS 140-2 Level 3 hardware security modules.
Access control
Least-privilege access, role-based controls, and audit logging across all systems handling customer data.
Tenant isolation
Customer data is logically isolated. No customer data is used to train shared models.
Incident response
Documented breach-notification process aligned to GDPR (72-hour), DORA and NIS2 obligations.
Each statement above must be backed by an actual implemented control before publication. Confirm with engineering and reflect only what is in place today; mark anything aspirational as roadmap.
Documentation

Available on request.

Compliance and security documentation for procurement and due diligence. Request via your account contact.

Data Processing Agreement
GDPR Article 28 · included by default
View →
Security Overview
Architecture, controls, residency
Request →
EU AI Act Art. 53 Documentation
GPAI transparency posture
Request →
Subprocessor List
Current, with change notifications
Request →
Privacy Policy
How we handle personal data
View →
Records of Processing (RoPA)
GDPR Article 30 · on request
Request →
Contact

Security & compliance questions?

Reach our compliance team directly.

admin@transtarnetworks.eu