generated: '2026-09-11' method: searched source: https://www.entergram.com/security trust_page: https://www.entergram.com/security certifications: [] compliance_programs: - name: GDPR status: aligned note: Self-attested alignment stated on the security page; no third-party certificate published. controls: - Encryption at rest with AES-256-GCM (Telegram session custody) - TLS encryption in transit (HTTPS everywhere) - Dedicated proxy IP per connected Telegram account - Least-privilege, scoped and audited access to decryption - Workspace isolation (a key from workspace A cannot access workspace B) - Configurable API-key/OAuth TTL, optional IP allowlists, instant revocation, audit logging note: >- No SOC 2, ISO 27001, PCI or HIPAA certification is claimed. The security posture is described in prose on the security page rather than in a formal trust portal with downloadable reports.