Security and compliance at AstraCore
How we protect your customers' data, where it lives, and how our AI agents meet EU requirements.
EU-only data residency
All customer data is stored and processed exclusively within the European Union. We do not transfer customer data to third countries.
Encryption
Data is encrypted in transit with TLS 1.3 and at rest with AES-256. Encryption keys stay in the EU.
Access control and audit logging
Granular role-based permissions per user, team and module. Every login, configuration change and data access is logged and can be exported for compliance reviews.
GDPR
We process personal data in line with the GDPR and Bulgarian data protection law. When we process data on behalf of our customers, we act as a data processor under a written data processing agreement.
EU AI Act transparency
Our AI chat and voice agents are built for the transparency and human-oversight requirements of the EU AI Act: conversations can be escalated to a human agent, and every interaction is logged for review.
Availability
Enterprise plans include a 99.9% uptime commitment with dedicated support, incident response and disaster-recovery failover.
Documents and questions
For our data processing agreement, list of sub-processors or a security questionnaire, contact us at team@astracore.eu.
Who is responsible
AstraCore services are provided by Astracore EOOD, EIK 201879628, VAT BG201879628, registered office: 20 Tsar Boris St., fl. 1, apt. 1, Misarya area, 8130 Sozopol, Bulgaria.