Skip to content
ENTERPRISE

Sovereignty your procurement team can sign.

When your customer's counsel asks where identity data lives and which law can reach it, "an EU region of a US provider" is not an answer. Adetio is built, operated and hosted in the European Union — so the answer is one sentence, and it holds up in the contract.

THE PROBLEM

Three questions that stall European deals.

Which jurisdiction can compel access?

US providers answer to US law wherever the servers sit. Adetio is designed to sit outside the reach of the US CLOUD Act — the whole company, not just a region flag.

Where exactly does identity data live?

In the EU region you choose, Frankfurt or Paris — sessions, profiles and audit logs together. Your team can verify it from the network tab, and your contract can pin it.

What happens if we leave?

Full export through the API, password hashes included. The exit path is a shipped product feature — which is precisely why you can commit.

SECURITY REVIEW

What your security review will find.

Not a brochure — the controls as built, each visible in the live demo right now.

Step-up re-authenticationkey rotation, recovery codes and deletions demand a fresh proof of identity.

Organization-enforced MFAno second factor means an enrollment-only session — a capability limit, not a nag.

Passkeys / WebAuthnphishing-resistant passwordless sign-in, user verification required.

Audit trailevery identity event, queryable per tenant and user, stored in your EU region.

Signed webhooksHMAC-signed deliveries, hardened against SSRF.

Reveal-once API keyssecrets shown once, stored only as hashes; rotation is one click.

GDPR erasure & exportproduct features, not support tickets.

Per-tenant themingyour customers see your product, not ours.

MIGRATION & EXIT

Easy to arrive. Easy to leave. That's the point.

You already have auth in production — so the real conversation starts with migration, and the real trust question is the exit. Both are product features.

IN

Arrive without password resets

Import users together with their existing password hashes through the API — bcrypt imports verify natively on first sign-in. No mass-reset email, no churn on day one.

Guided migration tooling for Auth0, Cognito and Firebase follows launch.

OUT

Leave with everything

A full export through the API — users, profiles and password hashes included, admin- and step-up-gated. If we stop earning your stay, you walk away whole.

Live in the product today, not a contract promise.

THE PAPERWORK

Everything procurement asks for, with honest status.

What exists is linked. What is planned says planned — the same rule we apply everywhere on this site.

Art. 28 GDPR terms, in full; signed with the operating entity at launch
Draft published
every subprocessor, all EU-based
Published
written for your security team
Published
SOC 2 Type II
controls built in from the start; certification follows launch
Planned
ISO 27001
on the compliance roadmap, not on the wall yet
Planned
Security questionnaires
send yours and we work through it with you
On request
WORKING WITH US

We are pre-launch. Here is exactly what that means.

01

Talk to us

Tell us about your stack, your regulators, and the contract that raised the jurisdiction question — and ask us anything your review needs.

02

Evaluate during hardening

We are in closed hardening before public launch. Waitlist teams get early access first — real tenant, real API, your data in your region.

03

Keep your launch rate

Pricing is confirmed the day we open, and early-access accounts keep the rate they join at — the same commitment published on the pricing page.

QUESTIONS YOUR TEAM WILL ASK

Straight answers.

Where does our users’ data actually live?

In the EU region you pick — Frankfurt or Paris today — and it stays there: sessions, profiles and audit logs alike. A region move is an operation we perform on request; there is no silent replication elsewhere.

Who operates Adetio?

A European team, on European infrastructure, under European law. The operating legal entity is published before launch, and every legal document on this site is shown in full, in draft, so you can read the terms we intend to launch under.

Do you support enterprise SSO (SAML / OIDC)?

The SSO connection layer is built into the platform today, and it will not be metered per connection. The self-serve SSO portal your customers configure themselves ships shortly after launch — that is roadmap, and we say so.

What about SCIM provisioning?

On the roadmap for the first post-launch release, alongside the SSO portal. If SCIM is a hard requirement for your timeline, tell us — it shapes the order we build in.

Can we get out if we need to?

Yes, completely: full export through the API including password hashes, gated behind admin rights and step-up re-authentication. Exit is a product feature — it is the strongest honesty guarantee we can give you.

A question we didn't answer? Ask us directly — we reply ourselves.

Bring your compliance team. We like the hard questions.

Built and tested, in closed hardening before public launch. Enterprise evaluations start from the waitlist.