Where your data lives and how it is protected
How Amistio stores your data, encrypts your credentials under a key that belongs to your account, and approaches European data protection. This page describes what the platform does today; it is not a legal certification.
Data residency — hosted in Germany
Amistio runs on Microsoft Azure in the Germany West Central region. Your agents, agent data, and encrypted credentials are stored on this deployment inside the European Union.
We do not copy your agent data to other regions. If that ever changes, we will say so here before it takes effect.
Encryption at rest
Provider credentials you save (the tokens and keys for the services you connect) are encrypted with AES-256-GCM before they are written to the database. The plaintext value is never stored, never written to logs, never included in run records or previews, and never returned to your browser — you only ever see a masked hint such as ••••1234.
When an agent runs, a credential is decrypted transiently in memory only to make the API call it was created for, and only for the service it belongs to.
Your own key — and you can rotate it
Every account has its own encryption key. Your saved credentials are encrypted under your key, not a single shared one, so one account's key can never read another account's data.
You can rotate your key at any time from the Connections page. Rotating generates a fresh key, re-encrypts all of your connections under it in a single step, and discards the old key. Your connectors are briefly unavailable while the re-encryption runs.
Your data and your rights
You own the agents and connections you create. You can delete any connection at once, which removes both its metadata and its encrypted material, and you can delete your agents and their data.
To request export or deletion of your account data, contact hello@lamplitlabs.com and we will action it.
Built for GDPR
Amistio is built with European data protection in mind: data residency in Germany, encryption at rest, per-account keys, data minimization (we keep a masked hint rather than your token), and deletion on request.
"Built for GDPR" describes how the platform is designed. It is not a certification or a legal determination of compliance, and it is not legal advice. If you need a Data Processing Agreement for your organization, contact us.
Infrastructure and subprocessors
Hosting and storage are provided by Microsoft Azure (Germany West Central). Sign-in is provided by Clerk. Optional, consent-gated analytics use Google Analytics and Microsoft Clarity; nothing is tracked until you accept analytics.
Model providers process the content an agent sends them only when an agent runs, using the model you configure. We will keep this list current as the platform evolves.
Contact
For any question about data protection, security, or a Data Processing Agreement, contact hello@lamplitlabs.com.