---
canonical: https://enum.co/security
locale: en
---

**Security by Design**

# Security

Security is built into enum's architecture from the ground up, from immutable infrastructure to per-customer isolation.

enum runs an enterprise-grade security and compliance posture for its European public cloud, on its own infrastructure in an NTT Tier III+ data center in Frankfurt, Germany, under German and EU law with no US CLOUD Act exposure. It covers isolated control planes per customer, immutable node operating systems, and encryption in transit and at rest, aligned with GDPR, NIS2, and DORA.


### Infrastructure Security

- **Immutable Infrastructure**: Where possible, systems are not manually modified or patched, but completely redeployed. This reduces the attack surface and eliminates configuration drift.
- **Tenant Isolation**: Strict logical isolation between customers at network and compute level. No cross-tenant access.
- **VPC & Network Isolation**: Each customer receives a dedicated Virtual Private Cloud with fully separated address space at Layer 2 and Layer 3.
- **European Infrastructure**: Own servers in Germany. No US cloud provider. No US Cloud Act.
- **Container Image Security**: Automated vulnerability scanning of all container images.
- **Supply Chain Security**: Signed artifacts, verified base images, traceable build pipelines.

### Physical Security

- **Tier III+ Data Center**: Frankfurt, redundant power and cooling systems.
- **24/7 Access Control**: Physical access controlled and logged.
- **Environmental Monitoring**: Temperature, humidity, smoke, continuously monitored.

### Data Protection

- **Encryption at Rest**: Storage layer and all node disks fully encrypted.
- **European Data Sovereignty**: GDPR is built into the architecture: no data processing outside the EU, no US dependencies, no CLOUD Act exposure.
- **Data Residency**: Data does not leave Europe. Full control over storage location.

### Access Management

- **OIDC-Based Access**: Infrastructure access via OpenID Connect.
- **RBAC**: Fine-grained, role-based access control.
- **Multi-Factor Authentication**: 2FA/MFA at all levels. FIDO2 hardware keys as standard.
- **Audit Logs**: Traceability of security-relevant access and changes across all platform components.

### Monitoring & Response

- **24/7 Monitoring**: Continuous monitoring of the entire platform infrastructure with automated alerts.
- **Network Visibility & Anomaly Detection**: Network anomaly detection based on flow data. Automated alerts for suspicious traffic patterns.
- **Incident Response**: Defined incident response procedures. Direct communication in case of emergency. Post-incident analysis and documentation.

### Compliance & Certifications

What enum fulfills and where data center certifications apply.


### Security Contact

Do you have security questions or want to report a vulnerability? Our security team is here for you.

Email: security@enum.co
security.txt: Security.txt

### Responsible Disclosure

The security of our platform and our customers' data is our highest priority. We value the work of security researchers and the community who help us identify and fix vulnerabilities.


#### Scope


**In-Scope**

- enum Cloud Platform (*.enum.co, *.enum.cloud)
- enum API and Console
- enum Kubernetes Engine, enum Object Storage, enum Compute, enum Network, enum VPC, enum DNS, enum CDN, enum Cloud WAF
- Network infrastructure and edge components

**Out-of-Scope**

- Social engineering, phishing or physical attacks
- Denial-of-Service attacks (DoS/DDoS)
- Spam or mass registrations
- Vulnerabilities in third-party software not operated by enum
- Vulnerabilities requiring physical access to devices or infrastructure

#### Rules

- If you encounter customer data during testing, stop immediately and report the vulnerability.
- Do not perform any actions that could affect the availability of our services.
- You may only interact with accounts you own or with explicit written permission.
- Do not disclose vulnerability details before we have fixed the issue and given you clearance.
- We ask that you report vulnerabilities promptly after discovery.
- No stunt hacking, no extortion, no leverage.

#### Our Promise

- We consider good-faith security research to be authorized activity, even if it technically violates our terms of service.
- We will acknowledge receipt of your report within 48 hours.
- We will keep you updated on the status of the fix.
- We will not take legal action against you as long as you comply with this policy.
- We compensate reported vulnerabilities. The amount depends on severity and report quality. We will inform you on a case-by-case basis.

#### Reporting

Please report vulnerabilities via email to:

security@enum.co


**Please include in your report:**

- Description of the vulnerability
- Steps to reproduce
- Affected systems or endpoints
- Potential impact (assessment)
- Proof of Concept if available (screenshots, logs, code)

If possible, encrypt your email with our PGP key:

