entrilla.

Straight answers for the person told to “check this Entrilla thing”.

No badge-waving. This page answers what a reviewer actually asks, in the order they ask it — and where we don't have something yet, we say so, with a plan.

01Where is the data?

On your own single-tenant instance — your own application and your own database, hosted in Sydney, Australia. There is no shared database and no shared application: each customer's Entrilla is a separate deployment, so another customer's bug or breach cannot reach your data.

The account service (app.entrilla.com) holds accounts, subscriptions and billing — never workflow data. That boundary is architectural, not policy: the account service has no route to the contents of your instance.

02Who can see it?

Inside the product, a five-level permission ladder controls who sees what — including who sees pay rates. Entrilla staff access your instance only for support, with your consent, and it's logged.

03What does the AI see?

Workflow text is sent to Anthropic's API for analysis under commercial terms: no training on your data, no retention beyond processing. Responses return to your instance and nothing is kept. Your data is never used across customers.

04Is it encrypted and backed up?

TLS on every connection; encrypted at rest. Cloud instances run nightly per-tenant backups with 30-day retention and monthly restore tests — and we'll publish the date of the last successful restore test here, because a tested backup is worth more than a badge.

05What happens if we leave?

One-click export of every workflow, anytime. Your data is deleted 60 days after cancellation, confirmed in writing.

06Certifications — the honest answer

We operate SOC 2-aligned controls from day one — audit logging, access reviews, tested backups, change management — and certification (SOC 2 or ISO 27001) begins with our first enterprise engagement.

We answer any security questionnaire within five business days. Ask us anything on a call and you'll get a straight answer.

07Enterprise access management

Enterprise plans include single sign-on with automatic user provisioning and de-provisioning from your identity system.

08Who touches our data (subprocessors)
SubprocessorPurposeData touchedRegion
Fly.ioTenant instance hostingAll customer instance dataSydney, AU
AnthropicAI analysisWorkflow text during analysis — commercial API terms prohibit training on customer data; nothing is retainedUS (processing only)
StripePaymentsBilling details (card data never touches Entrilla)AU entity
CloudflareDNS, TLS, static siteTraffic metadataGlobal edge
SentryError monitoringTechnical error context (scrubbed)US

Additions are announced 30 days ahead by email to account owners. Security researchers and reviewers: security@entrilla.com.

Put your reviewer on the demo call — we like hard questions.