Security and data protection, by default
Locanium processes location and identity data on your behalf, so security isn’t a feature here — it’s the baseline. This is how we protect every request, and the paperwork to prove it.
The safest data is the data we don’t keep
Validation and geolocation are stateless by design. We resolve your request and return the answer — the email, phone, IP or VAT number you send isn’t stored, profiled or sold.
Processed in-memory
Validation and geolocation payloads are resolved in-memory and returned — not written to disk or added to a profile after the response.
Never sold or shared
Your lookups are yours. We don’t build, enrich or trade data profiles, and we never resell what you send us.
Minimal logging
Operational logs only — scrubbed of the values you send and kept on a short retention window you can review.
Security built into every layer
Encryption everywhere
TLS 1.3 in transit and AES-256 at rest. Every connection and every stored byte is encrypted.
Access control
Least-privilege access, SSO and MFA for staff, and scoped API keys you can rotate or revoke instantly.
Resilient infrastructure
Hardened, isolated infrastructure across multiple regions with automated backups and failover.
Monitoring & alerting
Centralized logging, anomaly detection and 24/7 alerting, with DDoS protection at the edge.
Vulnerability management
Continuous dependency scanning, regular third-party penetration tests and a documented patch process.
High availability
A 99.99% uptime SLA backed by a public status page you can subscribe to.
Built for regulated teams
We support your compliance obligations and give you the documents to prove it — not a checkbox, the real paperwork.
- GDPR-aligned processing — you are the controller for your users’ data, we are the processor.
- EU data residency available on eligible plans.
- A custom Data Processing Agreement (DPA) on request.
- A published, up-to-date sub-processor list — no surprises.
- 99.99%
- Uptime SLA
- AES-256
- Encryption at rest
- EU · US
- Data regions
- <40ms
- Median response
Responsible disclosure
Found a vulnerability? We investigate every good-faith report, respond within 3 business days, keep you updated, and won’t pursue researchers acting in good faith.