Security and GDPR

Built so a compliance officer can read the architecture and nod.

A short summary of how Eidoscore is operated. For pilot teams we provide a fuller security note on request.

  • Public data sources only, with a documented lawful basis per collector.
  • Retention rules separate raw data, derived insights and reports.
  • Audit trail on every alert, review and action.
  • Single sign-on and encrypted secret storage.
  • EU-hosted infrastructure, GDPR-aligned by default.
  • Nothing is published or sent externally without a human approving it.
Infrastructure

Hosting and residency

Eidoscore runs on infrastructure located in the European Union. We operate our own stack rather than assembling a chain of third-party services, so collected content, derived insights and reports stay on systems we control, inside the EU. We name the provider and the specific region in the security note we share with pilot teams, and in any contract. We will not move your workspace to a different region without telling you first.

Data

Data we collect and how long we keep it

Eidoscore collects publicly accessible content only. Raw collected content is kept for a limited period; derived insights and reports are kept longer for trend analysis; retention is documented per workspace and agreed in your contract.

GDPR

Political data and the GDPR

Content revealing political opinions is special-category data under the GDPR. Eidoscore’s default is to monitor topics, narratives and communities, not individuals. A Data Protection Impact Assessment is completed before any scaled monitoring of political content for a client, and our architecture is GDPR-aligned by design. We say GDPR-aligned deliberately: compliance is a property of a deployment and its paperwork, not a badge, and we will walk your DPO through ours.

Vendors

Subprocessors

We keep the subprocessor list short, and we will tell you what is on it. Hosting and storage sit inside the EU on infrastructure we operate. Classification uses large language models, and model residency is a design decision we would rather be explicit about than quiet on: client content and live political data do not flow through a non-EU-resident model until our Data Protection Impact Assessment and residency requirements are satisfied. Before any contract begins we will tell you which models would process your data, where they run, and what the alternatives are. The current list, with each subprocessor’s role and location, is in the security note we provide to pilot teams.

Want the full security note?

Pilot teams receive a written security note covering data handling, access, retention and incident response. Email hello@eidoscore.ai or use the contact form.

Contact us