Security at Wonka AI
Wonka AI is built for European enterprises that handle sensitive data and require GDPR compliance, data residency controls and auditable access management.

Certifications
Wonka AI maintains ISO 27001 certification for information security management, full GDPR compliance and NIS 2 compliance. SOC 2 Type II audit is in progress.
ISO 27001 certified
Information security management system certified to ISO/IEC 27001.
GDPR compliant
Full compliance with the General Data Protection Regulation. Data Processing Agreement available.
NIS 2 compliant
Compliant with the EU Network and Information Security Directive (NIS 2).
Security practices
Hosting
- Azure West Europe (Microsoft Ireland) by default
- Cloudflare for CDN and edge delivery
- EU-based infrastructure with data residency controls
- Enterprise-grade Azure security and compliance
Data governance
- Encryption at rest (AES-256)
- Encryption in transit (TLS 1.2 or higher)
- Customer data is not used to train public AI models
- Data Processing Agreement (DPA) included
- Role-based access control and audit logs
Authentication & access
- Single Sign-On (SSO) support via Azure AD / Entra ID
- Multi-factor authentication (MFA) available
- Granular permission management per user and team
Compliance in progress
- SOC 2 Type II audit in progress
- Annual independent (external black-box) penetration testing
- Independent information security audits (Sencom)
- Annual sub-processor security reviews
- Continuous monitoring and incident response procedures
Important clarifications
Hosting default: Wonka AI is hosted in Azure West Europe (Microsoft Ireland) by default. This is not an on-premises deployment unless explicitly contracted.
Legal documents
A Data Processing Agreement is available on request.