Skip to content
Cuan
Security and GDPR

Money-grade security. Irish-law privacy.

We built Cuan the way you would want your bank built: EU-only, access control at the database, an immutable audit trail, and money that never touches our balance sheet.

Owners pay by SEPA Direct Debit into the OMC's PSRA client account; Cuan reads the bank by AIS and prepares SEPA files but never holds the money.Cuanreads and prepares, never holdsAIS · read onlyPSRA clientaccountOwnersSEPA Direct DebitSuppliersSEPA fileCuan never moves the money

Built like a bank, not a spreadsheet.

Cuan holds owners' financial data, arrears histories and the agency's reputation. Here is how each of those is protected.

EU-only hosting and subprocessors

Database, email and AI providers are all EU-based. Personal data is not transferred outside the EEA in normal operation.

GDPR processor model

Agencies and OMCs are the controllers. Cuan is the processor, under a DPA signed at onboarding.

Elevated-sensitivity data

Arrears and vulnerable flags get stricter access controls and full audit logging.

RLS at the database

Row-level security mirrors the role-based permission model. Access is enforced in the data layer, not just the UI.

MFA and SSO

SSO via Google or Microsoft, MFA enforced for any role with financial visibility, and magic-link with rate-limiting for owners.

7-year immutable audit log

Actor, action, object, before and after, IP and timestamp. Retained at least seven years, and never editable.

Bannered support access

Any Cuan support impersonation is visibly bannered and logged, every time.

WCAG 2.2 AA

Accessibility built into every owner and director surface, because the member base spans every age.

Reliability

A 99.9% availability target and a public status page. A failed direct-debit run is a severity-one incident, with customer-communication templates ready to go, because a money product cannot be casual about money.

The AI is approval-first

No AI output reaches an owner, director, contractor or solicitor without explicit human approval. Prompts and outputs are logged, PII is minimised, and every AI feature is toggleable per agency.

The questions your accountant will ask.

In the EU, end to end. Hosting and every subprocessor (database, email, AI) are EU-based, and the current subprocessor list is available to controllers, with notice of any change.
The short version

Built like a bank, by design.

EU-hosted, a GDPR processor model, row-level security, and a payment architecture where Cuan is never in the flow of funds.

EU-only

hosting and every subprocessor

7-yr

immutable audit log of every action

€0

client funds Cuan ever holds

99.9%

availability target, with a status page

Due diligence welcome

Bring your questions, and your accountant.

We will walk through hosting, the DPA, the audit log and the funds-flow architecture in detail. Money-grade scrutiny is exactly what we built for.