🛡️ Enterprise Data Protection

Security & Privacy Architecture

At Zeqalune, protecting your customer conversations and proprietary business documentation is built into every layer of our Cloudflare Edge infrastructure.

🇪🇺

1. European Data Residency (GDPR)

Zeqalune is strictly compliant with the EU General Data Protection Regulation (GDPR). All databases and conversation data reside in European datacenters (Frankfurt & Dublin).

🔒

2. Advanced Encryption Standards

All communications between your website visitors and Zeqalune are encrypted in transit via modern TLS 1.3 protocols. All persistent records are encrypted at rest with AES-256.

🚫

3. Zero AI Model Training on Your Data

Your proprietary company knowledge and customer chat transcripts are strictly isolated to your workspace and are never utilized to train public AI foundation models.

🏢

4. Multi-Tenant Logical Isolation

Every workspace is logically segregated with rigorous database boundary enforcement and support for Time-Based One-Time Password (TOTP) Two-Factor Authentication (2FA).

How Lune AI Protects Business Knowledge

Lune AI uses a strict Retrieval-Augmented Generation (RAG) pipeline:

  • Document Ingestion: Uploaded policies and crawled sitemaps are parsed into isolated vector embeddings scoped exclusively to your workspace ID.
  • Deterministic Answering: When a visitor asks a question, Lune AI retrieves only the matching excerpts from your verified docs, accompanied by source citations.
  • No Public Leakage: No other Zeqalune customer or external query can access your knowledge base index.

Widget Security & Isolation

The embeddable Zeqalune live chat widget is built with client-side security in mind:

  • Shadow DOM Isolation: Protects the chat window from external DOM manipulation or styling injection.
  • Zero Cookies Required: The widget operates with anonymous session tokens stored in local storage, minimizing unnecessary tracking.
  • Sub-30ms Edge Delivery: Delivered via Cloudflare's global CDN with automated DDoS protection and rate limiting.

Authorized Subprocessors & Hosting Architecture

To deliver high availability and global sub-30ms latency, Zeqalune engages vetted third-party subprocessors operating under strict Data Processing Agreements (DPA):

SubprocessorPurpose / RoleData Center RegionSecurity Certifications
Cloudflare, Inc.Global Edge CDN, Edge Workers, D1 SQL, R2 StorageEuropean Union (Frankfurt & Dublin)ISO 27001, SOC 2 Type II, PCI-DSS
Stripe, Inc.PCI-DSS Payment Processing & Billing InvoicesUnited States / GlobalPCI-DSS Level 1, SOC 2 Type II
Resend Inc.Transactional Email Notifications & Inbound SMTPEuropean Union / USSOC 2 Type II, GDPR Compliant
Google Cloud & AI ProvidersSemantic Vector Embeddings & RAG InferenceFrankfurt (EU) / Global EdgeISO 27001, SOC 2 Type II, Zero-Training Agreement
Need an executed Data Processing Addendum (DPA) or custom enterprise audit?Request DPA (privacy@zeqalune.com) →

Questions About Security?

Review our documentation or reach out to our security engineering team.