Advanta Legal · Security overview

Security overview

Last updated: 3 May 2026 · Version 1.0 · For the current security questionnaire pack, contact diogo@advanta.pt

This document summarizes Advanta's technical and organizational security measures. It is provided for prospective customers, security questionnaires, and audit reviewers. For the canonical, authoritative version, customers should refer to the executed Data Processing Agreement (DPA).

Compliance posture

StandardStatusDetail
GDPR (Reg. 2016/679)CompliantDPA available; DSR mechanisms (export, erasure) implemented; CNPD-aware DPO appointed
SOC 2 Type IQ3 2026Vanta engagement; observation period commences Q1 2026
SOC 2 Type IIQ1 2027Following Type I, after 6+ months operational evidence
ISO/IEC 27001:2022When requiredEngaged when first tier-1 customer contractually requires it
DORA (Reg. 2022/2554)DocumentedICT third-party risk classification document available; supports financial-entity register obligations
PCI DSSOut of scopeCard data is processed solely by Stripe (PCI Level 1); Advanta never touches PAN data

Data protection

Encryption in transit

TLS 1.3 enforced on all customer-facing endpoints. TLS 1.2+ for internal services. Strict-Transport-Security with one-year max-age + preload.

Encryption at rest

AES-256 with customer-managed AWS KMS keys (CMK) for RDS, S3, Secrets Manager, EBS, and ElastiCache. Annual key rotation enabled.

BYOK (Bring Your Own Key)

Available on Enterprise plans. Customer's KMS key encrypts the customer's tenant-isolated data. Lifecycle managed by the customer.

Backups

RDS continuous backup with 7-day retention + 35-day point-in-time recovery. Encrypted. Tested quarterly.

Audit log

Compliance-grade audit log with 7-year WORM retention via AWS S3 Object Lock (compliance mode). SHA-256 signed records.

Data residency

All Customer Data stored in eu-central-1 (Frankfurt). Cross-border transfers governed by EU SCCs (2021/914) where unavoidable.

Network security

Identity & access management

Multi-tenant isolation

Advanta is a multi-tenant SaaS. Customer Data isolation is enforced at three layers:

  1. Application layer: every database query filters by tenant_id explicitly
  2. Database layer: Postgres Row-Level Security (RLS) policies; the runtime DB role does not have BYPASSRLS
  3. Engine roles: migration role (privileged) is distinct from runtime role (RLS-bound)

Customers requiring stricter logical separation may opt into dedicated schema (Enterprise) or dedicated database instance (Tier-1 Enterprise) modes.

Application security

Penetration testing

Vulnerability disclosure

We welcome responsible disclosure of security vulnerabilities. Email security@advanta.pt (PGP key on request) with details. We commit to:

Incident response

Business continuity

ComponentRTORPO
RDS Postgres5 min5 min
API runtime (ECS)1 minn/a
Audit logn/a (immutable)0
Region failure (manual standby promote)4 h1 h

Insurance

Personnel

Audit & assurance

Customers on Enterprise plans may, with reasonable advance notice and during normal business hours, conduct audits as set forth in the DPA. We provide:

Contact

Security: security@advanta.pt
Data Protection Officer: diogo@advanta.pt
Vulnerability reports: security@advanta.pt