Security & Trust Center

Your fleet data,
handled like it matters.

Talos ingests telemetry from tens of thousands of machines. We treat that data the way our customers treat their equipment — carefully, with a paper trail, and with someone on call when it counts.

Data hosting
EU.
Encryption
TLS 1.3.
Uptime target
99.9%.
Backups
Daily · PITR.
Security posture

Four pillars we don't cut corners on.

What we do by default for every customer, not just enterprise ones.

Encryption everywhere.

In transit and at rest, with modern ciphers and short-lived credentials for every service-to-service call.

  • TLS 1.3 for all public endpoints; HSTS enforced
  • AES-256 at rest for databases, object storage and backups
  • Managed KMS with rotation; no plaintext secrets in code or CI

Access, minimised.

Least privilege by default. Engineers get the access their job needs — and no more, checked quarterly.

  • SSO + MFA required for all internal tooling
  • Row-level security in the database, per-tenant scoping in the API
  • Just-in-time production access with full audit trail

EU-hosted infrastructure.

Primary data storage stays in the EU. No customer data leaves the region without an explicit contractual basis.

  • Azure regions in Western Europe (Netherlands) and North Europe (Ireland)
  • Standard Contractual Clauses for any non-EU sub-processor
  • Data residency commitments available for enterprise contracts

Observable & recoverable.

You can't protect what you can't see. Every service emits logs, metrics and traces — and gets tested backups.

  • 24/7 alerting with on-call rotation and incident runbooks
  • Daily encrypted backups with point-in-time recovery
  • Quarterly restore drills; documented RPO ≤ 1h, RTO ≤ 4h
Controls at a glance

The short answers procurement asks for.

If you need a full security questionnaire filled in, email security@talos.be — we usually turn them around in 3 working days.
AreaTalos today
Data hostingMicrosoft Azure, Western Europe (Amsterdam) primary, North Europe (Dublin) failover.
Encryption in transitTLS 1.3, HSTS preloaded, modern cipher suites only.
Encryption at restAES-256 for databases, object storage, backups and disks.
AuthenticationSSO (SAML / OIDC) for enterprise; password + MFA for standard accounts.
AuthorisationRole-based access with per-tenant scoping and row-level security in the database.
Audit loggingImmutable audit trail for authentication, permission changes and data exports.
BackupsDaily encrypted backups, 30-day retention, point-in-time recovery.
Uptime target99.9% monthly for the production API and web app. Public status page available on request.
Incident response24/7 on-call, ≤ 15 min acknowledgement for Sev-1, customer comms within 24h.
Vulnerability managementContinuous dependency scanning, quarterly external pen-test, annual review of security controls.
PersonnelBackground checks on hire, security training on onboarding and annually, signed confidentiality agreements.
Data deletionOn contract end, customer data deleted within 30 days from live systems and 90 days from backups.
Compliance

Where we are,
and where we're going.

We're honest about what's certified today and what's on the roadmap. You can see the same status here that we share in our security questionnaires.

GDPR (EU 2016/679)

We act as processor for customer telematics data. DPA available on request or via the site.

In place
ISO/IEC 27001

Information Security Management System scoping complete. External audit targeted for H2 2026.

In progress
SOC 2 Type II

Controls mapped; observation window planned for 2027 once ISO 27001 is certified.

Planned
EU Data Act readiness

Data portability APIs and machine-generated data access flows reviewed against the EU Data Act.

In progress
NIS2 alignment

Incident reporting, supply-chain security and governance mapped against NIS2 obligations.

In progress

Sub-processors.

The infrastructure and service providers that process customer data on our behalf are listed in the Data Processing Agreement, with location and purpose for each.

Read the DPA
Responsible disclosure

Found something? Tell us.

We welcome reports from security researchers. If you've found a vulnerability in Talos, email security@talos.be with a description, reproduction steps, and any impact you can demonstrate.

We reply within
1 working day.
Triage
≤ 5 working days.
Safe harbour
Yes, if in good faith.
Please don't

Access data that isn't yours, run automated scans that could disrupt service, or publish findings before we've had a chance to fix them.

Email security@talos.be