Trust is a feature.

Outsourcing your presence usually means handing over your keys and your data. Not here.

Giving your social media to an agency or a SaaS tool normally means handing over your provider keys, your audience data and your control — hosted wherever the vendor happens to run. Entradigm is built the other way around: your keys stay vaulted and yours, your data is EU-first, every published cycle carries its EU AI Act Art. 50 label, and you delete your account yourself in the app.

AI transparency, fail-closed

Every published cycle carries its EU AI Act Art. 50 label — fixed in code, not a setting.

The AI disclosure ships on the media itself as an on-slide footer badge, plus a disclosure sentence appended server-side to the caption in the post's own language. The wording is fixed and the label cannot be switched off: fail-closed, so a missing label stops the post instead of shipping without it. Where a network offers its own synthetic-media flag — TikTok, YouTube — Entradigm sets it at dispatch.

Your keys, vaulted. Your data, EU-first.

BYO keys are resolved only at the moment of use — never shown back, never logged.

Bring your own AI, voice and music keys and they live encrypted in a vault, read server-side only inside the step that needs them — never shown back, never logged, never stored in a workflow payload. All traffic runs over TLS 1.3. The database runs in an EU region, media rendering and GPU generation in EU Frankfurt, transactional email from the EU — and every sub-processor is named in the published register, with DPAs concluded before processing begins.

GDPR rights

Your data, your rights.

The core data-subject rights under GDPR are covered: you trigger the deletion of your account yourself in the app (Settings → Account); access and portability we grant on request via Contact, answered within 30 days per Art. 12(3) GDPR.

Art. 15 — Access

Data access

On request via Contact you receive a structured copy of the data we hold for your tenant.

Art. 17 — Erasure

Account deletion

You delete your account yourself in the app (Settings → Account), confirmed with a fresh second factor. Deletion cascades across our systems including rendered media, removes your posting-provider profile on a best-effort basis, and hard-deletes after a 30-day grace period — each step recorded in an erasure audit log.

Art. 20 — Portability

Data portability

On request via Contact you receive your data in a machine-readable format — for migrating to another provider.

EU AI Act — Article 50

AI-generated content is labelled — by the pipeline, not by policy.

The EU AI Act (Art. 50) requires that AI-generated content be labelled as such. Entradigm enforces this in the publishing pipeline: every published cycle carries a footer badge rendered into the media itself plus a disclosure sentence appended to the caption in the post's language. The wording is fixed and the presence of the label cannot be switched off — if the disclosure cannot be applied, publishing fails rather than going out unlabelled. Where a platform offers its own synthetic-media flag (TikTok, YouTube), Entradigm sets it at dispatch.

Sub-processors

Who touches your data — visible, not hidden.

Exactly who processes which data, in which region and on which legal basis, is published in two places: the category table in this site's Privacy Policy and the full named register in the app's privacy policy. The overview below summarises that register; it invents nothing.

Infrastructure

Cloudflare

Application edge, storage and embeddings (USA + EU). EU region available.

Data & auth

Supabase

Database + authentication. The database runs in the EU region.

AI drafting

Anthropic

Script and slide drafting (USA, EU Standard Contractual Clauses). Bring-your-own is live: add your Anthropic API key and cycles run on your account — verified on save, stored encrypted, never displayed again. Anthropic does not use these requests to train models.

Media rendering

AWS

Video rendering and GPU media generation (voice synthesis, music) — EU Frankfurt.

Social publishing

Upload-Post (TONVI TECH SL)

Cross-platform posting via an EU provider (Spain) — engaged only when you connect accounts. Your social-network OAuth lives there, never inside Entradigm. Data-processing agreement concluded.

Web research

Exa

Public-web industry signals (USA) — runs only on your opt-in consent.

We conclude data-processing agreements before a sub-processor touches any data, base third-country transfers on EU Standard Contractual Clauses (2021/914) plus supplementary measures, and announce new sub-processors at least 14 days in advance.

Encryption & hosting

EU-first, encrypted, passwordless.

EU hosting

EU jurisdiction first

The database runs in Supabase's EU region, media rendering and GPU generation on AWS in EU Frankfurt, and transactional email is sent from the EU (Ireland). Cloudflare provides the application edge, with an EU region available.

Encryption

In-transit & at-rest

All in-transit traffic runs over TLS 1.3. Secrets — BYO keys and tokens — are encrypted at rest in Supabase Vault: never shown back, never logged, and resolved server-side only at the moment of use, never stored in workflow payloads or logs.

Sign-in

Passwordless + mandatory MFA

Sign-in via a one-time magic link plus a mandatory authenticator app (TOTP) as the second factor on every app session, with recovery codes and a fresh step-up before destructive actions like account deletion. There's no password that could leak, and the sign-in form is bot-protected.

Isolation

Tenant isolation

Every request re-resolves your workspace membership from the live database — never trusted from a token or cookie. Row-level security fails closed, and each tenant's media lives under its own storage prefix, which doubles as the single-prefix GDPR erasure path.

Cost caps & abuse controls

Spending fails closed. Always.

Per-cycle cap

A hard cost cap on every cycle

Every platform-managed cycle is subject to a hard $2.00 cost cap — the platform stops rather than overspending. And there is no silent overage on any plan: hard stop with an upgrade prompt, or a budget cap you set yourself.

Budget breakers

Daily + monthly circuit-breakers

Every metered path — generation, posting, music, knowledge-base processing, the docs assistant — sits behind daily and monthly budget ceilings that fail closed: if a breaker can't be read, the platform refuses the spend instead of allowing it.

Rate limits

Rate-limited surfaces

Sign-in, account recovery, lead capture, social-account connection and the agent API are rate-limited per IP or per tenant, and the public forms are protected by Cloudflare Turnstile.

Supply chain & engineering assurance

How the platform itself is built.

CI gates

Every change is gated

Static security analysis, dependency-vulnerability scanning, a seven-day quarantine on newly published dependencies, credential-leak checks and the full test suite run on every change — merges are blocked until green.

Signed releases

Signed commits, gated deploys

Commits are cryptographically signed, the main branch blocks force-pushes, and production deploys happen only through CI-gated release tags — no hand-pushed production code.

Environments

Production stays production

Production and test environments are strictly separated, with a runtime guard on every database call — test runs can never touch production data.

Legal

The documents in full.

You can find the full legal documents here: