Curious Endeavor
— Security & Data Protection Overview
Confidential · March 2026
Infrastructure at a Glance
■
EU-Hosted Infrastructure
Hetzner · Helsinki, Finland
■
TLS/HTTPS Everywhere
All connections encrypted in transit
■
SSH Key-Only Access
No password authentication
■
No Client Data Retained
Deleted after campaign delivery
Data Flow
Brandwatch
Export
CSV / data feed
→
CE System
EU · Helsinki
→
AI Processing
API calls only
→
Campaign
Output
Strategy + assets
→
Delivered
to Client
Source data deleted
Data enters EU infrastructure → processed → output delivered → source data permanently deleted
AI Subprocessors
Provider
Use
Security Posture
Anthropic
(Claude)
Strategy, analysis, copywriting
SOC 2 Type II
· No training on API inputs · Enterprise DPA
Google
(Gemini)
Image generation, research
SOC 2 · ISO 27001 · GDPR
· Enterprise DPA
Data Protection · GDPR
Processing primarily aggregated social intelligence — not individual PII
EU infrastructure — no cross-border data transfer issues for storage
Prepared to execute a Data Processing Agreement (DPA)
Data minimization: only process data required for campaign output
Retention policy: all source data deleted after campaign delivery
AI providers accessed via API only — no data used for model training
What We Commit To
Sign your standard Data Processing Agreement
Work within your vendor security framework
All client data deleted after each project delivery
SOC 2 Type II on our roadmap as partnership scales