Your sales calls and meetings deserve privacy. Here’s how we keep your data safe inside the EU.
HTTPS everywhere; data at rest encrypted with AES‑256.
All customer data stays in Azure France Central (EU). Encrypted daily back‑ups in West Europe.
OAuth 2.0 / OIDC sign‑in with short‑lived JWT tokens.
Audio 30 days (customisable). Logs 2 years for audit. Delete‑on‑request.
All traffic between your browser and Teneks is protected with HTTPS/TLS encryption. Data stored on our servers is encrypted using AES-256 encryption. We host our platform on Microsoft Azure in the France Central region, which provides built-in security features including DDoS protection. Daily backups are automatically replicated to West Europe for data protection.
Teneks can automatically detect and redact personally identifiable information (PII) from exported transcripts to help protect customer privacy and support compliance requirements.
For platform improvements, we use only fully anonymised and aggregated usage data — such as feature‑usage patterns, page views and session durations — that describes how users interact with the platform interface. We never use customer content data (audio, transcripts, conversation analytics) for platform improvement. All usage data is aggregated so that it cannot be traced back to any individual or organisation (GDPR Recital 26).
Users sign in securely using Google or Microsoft accounts through OAuth 2.0. This means we don't store your passwords - authentication is handled by these trusted providers. All API requests are protected with JWT tokens to ensure only authorized users can access your data.
Access to customer content data (audio recordings, transcripts, conversation analytics) is strictly controlled:
Teneks employees do not have access to your audio recordings, transcripts or conversation analytics. Technical infrastructure access is limited to system administrators who can only view anonymised metadata for operational purposes.
Our application follows secure coding practices and we regularly update dependencies to address any security vulnerabilities. Azure provides the underlying infrastructure security including network protection and access controls.
Platform health is monitored continuously; security alerts are reviewed by an on‑call engineer. We commit to acknowledging any critical vulnerability report within 24 hours.
Our compliance roadmap prioritises EU regulations first, followed by internationally recognised certifications.
| Standard | Status | Target Date | Scope |
|---|---|---|---|
| GDPR | ✅ Operational | Ongoing | Data protection & privacy |
| EU AI Act (limited-risk) | ✅ Aligned | Ongoing | AI transparency & safety |
| ISO 27001 | 🚧 Audit prep | Q4 2026 | Information security management |
| SOC 2 Type II | 📋 Planned | H1 2027 | Security, availability & confidentiality |
| OWASP Top 10 | 📋 Scheduled | Dec 2026 | Application security testing |
| Cyber Essentials Plus | 📋 Planned | Q3 2026 | Basic cyber security controls |
We use a small number of vetted sub-processors, each bound by a data processing agreement under GDPR.
| Vendor | Service | Data Location | Data Types |
|---|---|---|---|
| Microsoft Azure | Cloud hosting & storage | France Central / West Europe | All platform data |
| Stripe | Payment processing | Ireland (EU) | Billing & payment data |
| Google Workspace | OAuth authentication | EU regions | Email & profile data only |
| Microsoft 365 | OAuth authentication | EU regions | Email & profile data only |
We will update this list within 30 days if additional analytics, monitoring, or support vendors are engaged. Customer data is never shared with marketing or advertising platforms.
We use Azure Monitor and automated dependency scanning to detect security issues early.
Platform health is monitored continuously; security alerts are reviewed by our engineering team. We commit to acknowledging any critical vulnerability report within 24 hours and will provide customer notification for any incident affecting data security.
Our infrastructure runs on Microsoft Azure with built-in redundancy and backup across two EU regions.
As a growing startup we continue to strengthen our disaster recovery. Azure's managed infrastructure gives us a strong baseline for data protection and service continuity.
The detailed Teneks Security White Paper is not publicly available. It is available upon request for qualified security, procurement, and legal reviews. Contact security@teneks.ai.
Found a vulnerability? Email security@teneks.ai. We'll respond within one business day.