Trust & Security
Last updated: September 2026
Greyrox exists to give you visibility and control over the AI your company uses — which only makes sense if we can show the same about ourselves. This page covers where your data lives, who touches it, how long we keep it, and where our certification work stands. If something here isn't detailed enough for your own review, ask us directly at info@greyrox.com.
Where your data lives
Greyrox is hosted entirely within the EU. Data about the AI tools and agents Greyrox discovers in your company — and everything derived from it, including audit logs and cost data — is stored and processed on EU infrastructure. It does not leave the EU as part of how Greyrox operates.
Subprocessors
No third party subprocesses the customer data that runs through the Greyrox platform — the tool discovery, permissions, audit logs, and cost data described elsewhere on this site stay inside infrastructure we operate ourselves.
This is separate from the handful of services that support greyrox.com and the sales process itself — Google Fonts, and Calendly for booking a demo — which are covered in our Privacy Policy, since they only ever see what you choose to share with us directly, not your company's AI usage data.
Encryption
Data is encrypted both in transit and at rest, throughout the platform.
Retention
We retain discovery, permissions and audit data for six months. If you ask us to delete it sooner — for a specific record, or on offboarding — we do that on request rather than waiting out the six months.
Certifications
Our SOC 2 Type 1 audit is in progress. We'll update this page — and tell existing customers directly — once it's complete. If you need our current audit status or documentation for a procurement review in the meantime, ask us and we'll share where things stand.
Incident response
We maintain an incident response process with a defined SLA, and notify affected customers without undue delay if something goes wrong — in line with the GDPR's own 72-hour requirement for notifying regulators of a personal data breach.
Reviewing Greyrox for procurement or a security questionnaire? This page is a summary, not a substitute for your own diligence. Email info@greyrox.com and we'll walk through specifics, share our SOC 2 status, or fill out your questionnaire directly.