European to the core

Your login system holds the smallest and most sensitive dataset you own: who your users are, and how to become them. With a US-owned provider, US law reaches that data wherever it is stored. The region you picked at signup does not decide who can be ordered to hand it over; the owner does.

Three phrases that sound the same

Almost every auth vendor can say something European about itself. The words are not interchangeable, and only one of them decides who can compel your data.

  • EU-hosted is a postcode. It says where the servers sit. A US company can rent a data centre in Frankfurt tomorrow.
  • EU-operated is staff. It says who administers the systems day to day. Useful, but not decisive: the people holding the keys can work for a parent company elsewhere.
  • EU-owned is jurisdiction. It says which courts can issue an order the company must obey. It settles the question, and most vendors cannot claim it.

Authalla is all three. Below is the proof for each, so you can check rather than take our word for it.

The proof

EU-owned. Authalla Oy is a Finnish limited company, business ID 3597022-6, registered in Helsinki and entered in the Finnish Trade Register. It is owned by its founders. There is no US parent company, no US holding structure and no outside investors, so there is no US entity that could be ordered to produce your data, and nobody upstream of us who could be.

EU-operated. We run it ourselves, from Finland. Production access is tightly held and never leaves the company.

EU-hosted. The service itself, and everything we store, runs on infrastructure from Hetzner Online GmbH, a German company, in its Helsinki data centre. That covers the application servers, the PostgreSQL database your users live in and its backups, object storage for uploaded assets, and authoritative DNS for the domain.

The full list of every company involved, what each one does and where its ultimate parent sits, is on the subprocessors page. It is short, and we would rather you read it than trust this paragraph.

Where this claim stops

The claim has three limits, and we would rather list them here than have you find them yourself.

  • Identity providers you choose to enable. If you turn on Google, Microsoft, GitHub, Facebook, X or LinkedIn sign-in, or connect a customer’s enterprise IdP, that sign-in happens in that provider’s jurisdiction under their terms. That is your decision to make and your users’ data passing through someone else’s hands. Passkeys and email sign-in, the defaults, involve no identity provider but us.
  • Transactional email. Magic links and sign-in codes are delivered through Brevo, a French company, so your users’ email addresses reach it. That is what delivering an email means. Brevo is EU-owned, but it states that it stores data on its own servers and on Google Cloud in Belgium. The data stays in the EU; part of the infrastructure under it belongs to a US company. That is why our claim is precise about what we store, rather than broad about everything an address ever passes through.
  • Developer tooling. Our SDK ships through npm and the CLI through Homebrew, both US-operated. That is code travelling outward to developer machines. No customer or end-user data goes into either, and neither is in the path of a single sign-in.

What this does and does not do for your compliance

Using Authalla removes the third-country transfer question for your identity data. In practice, you need no transfer impact assessment for this dataset, and you do not depend on standard contractual clauses or an adequacy decision to cover it.

It does not make you GDPR compliant, and nobody can sell you that. It does not make you NIS2 compliant either. If you sell to enterprises, it answers one of the questions their supply-chain assessment will put to you, without a caveat.

And the part that is not about jurisdiction

There is a simpler reason to buy from a company nearby. When your authentication breaks at four in the afternoon, you call someone who works on the code, during your working day, under a contract governed by Finnish law. You do not file a ticket into a queue on another continent and wait out a first-response target.

Our phone numbers are at the bottom of the front page. They will stay there when we have enough customers to make that inconvenient.