Security and reliability
Your data, with the answers your IT team asks for
Where it is, who can access it, how it is protected, how it is recovered and how you take it with you if you ever leave. Straight answers, no marketing.
- Data hosted in the EU
- Two-factor authentication and sign-in with Microsoft or Google
- Permissions down to the value of a field
- Documented security controls
The problem
The question that stalls any purchase
Before signing, IT asks where the data is, who gets in, what the AI does with it and how you leave. Finding an inaccuracy here destroys trust in everything else. That is why this page tells it like it is.
Where your data is
In Europe, and kept separate
- SaaS service on Kubernetes in AWS, OVHcloud or Google Cloud, in a European region. As a project, also on-premise, with the data on your infrastructure
- A dedicated database for each customer
- Encryption in transit
- On top of that, attendo encrypts the credentials it stores: mailboxes, sign-in, telephony, webhooks and API, messaging, signing certificates and payments. Every update checks that none is left in the clear
- Encrypted backups, on demand and downloadable, and scheduled backups to your own S3 storage, which require a password and never leave unencrypted
- Attachments, PDFs, recordings and exports go to the installation’s storage, not to the web server’s disk. An export can be downloaded for one day, and audio sent for transcription is deleted afterwards
- Daily backups with retention and verified restores
- Anti-malware scanning of attachments
Who gets in
Every access, controlled and logged
- Password policy with rules, attempt limits and session expiry. If a password no longer meets the policy, the user must change it
- Nobody types someone else’s password, not even an administrator: when a person is added, they get a link to create their own, and the email is kept in the security audit
- Single active session: if another device takes over the session, every screen says so instead of treating as saved what was not saved
- Two-factor authentication by app or by email, with trusted devices, and mandatory per profile if you choose
- Sign-in with Microsoft Entra ID, Google or Auth0, including on the portals
- In the customer, supplier and partner portals, each person signs in with their own account and the same two-step verification. Their role and scope are checked on the server on every action, and removing their access ends their sessions
- Access log with IP address and device, and lockout after repeated attempts
- Security alerts by email, with your brand and in each person’s language
- Customer access codes that expire
Who sees what
Permissions down to the value of a field
Permissions have three layers: roles, user profiles and security templates by group and document type. Each person’s profile decides which menu, home pages, dashboards and reports they see. On top of that, field-value visibility decides, for example, that a technician only sees their own area or an external contractor only their own queue. It is enforced on the server and on every screen, download and report. And it does not just hide things: a value the person has not been granted is rejected on save.
The same goes for the customer portfolio: a sales rep with assigned customers only sees and changes the contracts, tags and figures of their own customers, also in reports, scheduled exports and the API.
- Settings for administrators only, including through the API. Importing and exporting data and managing the whistleblowing channel too, with no exceptions
- Sensitive screens, such as turning on modules, the flow editor or the system queues, always ask for an extra verification that cannot be removed from Settings
- API keys that can only do what you allow
- No dashboard can read credentials or technical data such as the IP address or the browser
What gets logged
What happened, who did it and when
- The timeline of every document, with author and time
- The history of every flow run
- The log of every AI operation: user, model and cost
- The delivery status of every email
- Every change to a contract: dates, price, item, supplier or deletion, in the history of its record
- A view of security measures designed for your IT team
- The acceptance of every legal text, with its signature and its evidence record
- The fingerprint of signed documents, and of timeline events and their evidence, stored on the blockchain to prove they have not changed
Artificial intelligence
AI, under control
AI is optional and turns off module by module. It uses your provider and your key, stored encrypted. Every operation is logged with its cost, under a spending limit that stops it. Anything that goes out to a customer waits for approval by default. And a rule in the code decides what data travels: the rows of your tables only go to Scaleway or to your Microsoft 365 Copilot.
What was sent to the AI and what it answered is kept for 90 days so it can be reviewed. After that it is cleared, and the figures remain: who, when, which model and how much it cost.
Online payments
Payments and web quotes
- attendo Pay collects payments through your own gateway. If the customer chooses to save their card, attendo only keeps the card brand, the last four digits and the expiry date
- Web quotes include security headers, and an expired link does not reveal who issued it
- Links to surveys, payments and documents are generated at random. A survey or web quote link stops working when its module is turned off, and anyone trying made-up links is slowed down
- Custom CSS for the portals and the whistleblowing channel is reviewed when it is saved: anything that loads files from other websites is rejected
- Exports store cells that start with “=” as text, and anything that arrives in an imported file is always shown as text
Reliability
Built so nothing gets lost
- Heavy work runs in queues with retries, not on the user’s screen
- Scheduled tasks catch up if they are delayed, instead of being skipped
- If your ERP goes down, changes wait in a queue and are applied when it comes back
- Every email has a delivery status and is retried if it fails. If a mailbox stops responding, attendo alerts you
- Updates do not touch your configuration
- No dashboard can slow the instance down: every query has a time limit. A slow screen is cut off with a notice and does not keep the others waiting
- Administrators see, in their own instance, how each scheduled task ran, what each queued process is doing and what is running slow
GDPR
Data protection
attendo processes your customers’ data as a data processor, with its data processing agreement and its list of subprocessors. Your data can be exported in full whenever you want. And if your organization needs a whistleblowing channel, it is built in: anonymous reports, managed only by administrators. No dashboard can read it, and its report shows nothing that identifies the whistleblower.
If you supervise your team with the task compliance module (Compliance · My team), the My team tab shows no data until an administrator accepts the supervision text in writing, and each person knows their supervisor sees that summary.
And if other companies serve your customers on your behalf, as partners, the relationship with each customer sets what the partner sees, what it does and whether it can access their personal data, and it has an end date.
The owner of the service and data processor is AxisOne Group SL.
Security framework
Documented, verifiable controls
Every attendo security control is documented in writing: access, permissions, traceability, backups, encryption and providers. We walk you through them in detail on a technical call, with the documentation your team needs.
The rest of the platform
And when you need it, the rest is already here
Frequently asked questions
Frequently asked questions
Do you have ISO 27001 or Spain’s ENS certification?
We do not. What we do is document every control in writing (access, permissions, traceability, backups, encryption and providers) and walk you through it on a technical call. If your tender requires a certificate issued by an accredited body, raise it with us from the start.
Can we require the whole team to use two-factor authentication?
Yes. You can make two-factor authentication mandatory per profile.
Does it integrate with our corporate directory?
For sign-in, yes: with Microsoft Entra ID, Google Workspace or Auth0. It does not create users or assign roles from the directory: each person exists in attendo first, with their profile.
Does any data leave the European Union?
Only through what you turn on. If you use AI with a provider outside the EU, it receives the structure and the text of the document at hand. The rows of your tables only travel to Scaleway or to your Microsoft 365 Copilot. You choose the provider according to your policy. Maps, WhatsApp and your email provider receive only what they need to work.
Can we take our data with us?
Yes, all of it, at any time.
What service level do you offer?
It is set in the contract.
Do you sign a data processing agreement?
Yes, it is part of the contract.
Request a demo
We answer your IT team’s questions
A technical call with the people who run the platform, and the documentation you need, under confidentiality.
- With your operation, not a generic demo
- A real person from our team replies
- No cold calls afterwards
Would you rather talk first?
- Phone +34 902 750 677 · +34 910 053 530
- Email sales@attendo.me
- Monday to Thursday 9:30 AM to 6:30 PM and Friday 9:30 AM to 2:30 PM (Spain time)