GDPR-native is the first sentence, not the footnote.
Remitto handles your carrier data and credentials. Everything is encrypted, EU-resident, access-scoped, and auditable — by design.
Posture
Built to move money, held to the standard that demands
Data residency
- All data stored in EU regions — database, object storage, and workflow orchestration.
- Your data never leaves the EU.
- Single-tenant isolation per organization, enforced at the data layer.
Encryption
- TLS 1.3 for all data in transit.
- AES-256 for data at rest.
- Carrier credentials encrypted and access-scoped per organization.
Access & accountability
- Role-based access control with least-privilege defaults.
- Every privileged action is written to an immutable audit log.
- SSO via your identity provider on higher tiers.
Compliance
- GDPR-native: clear lawful bases, data minimization, documented processing register.
- Responsible disclosure: security@remitto.io, 90-day policy.
Reporting a vulnerability? Email security@remitto.io.
Security your auditors
can verify.
Connect a carrier and see the audit trail for yourself. EU-resident, GDPR-native, free to start.