Only the approved slice
Investigators see mandate-scoped data: named custodians, systems and dates. Never open search across the company.
Security and governance
Sensitive evidence stays inside the customer environment and is released only through an approved, case-specific mandate.
Security-first. GDPR-first. Self-hosted.
Controlled by design
Four enforcement layers stand between an investigator and the evidence, and an audit spine records every action across all of them. An investigator cannot search the company because they hold a platform role.
You stay the controller: Telha runs inside your environment, so there is no vendor processing and no data leaves your jurisdiction. The regulation's principles aren't a compliance layer; they are the platform's mechanics.
Investigators see mandate-scoped data: named custodians, systems and dates. Never open search across the company.
Every mandate records why the data is processed and who approved it, before any access opens.
Cases end, and access ends with them, automatically, under retention and legal-hold rules you control.
Self-hosted deployment keeps evidence in your jurisdiction. Third-country transfer never enters the picture.
Who accessed what, when, under which mandate, exportable as your record of processing for investigations.
Answer subject access requests from the same indexed, versioned memory, without a company-wide fire drill.
Not a separate settings page added after the workflow.
Investigators receive access to the approved case, not unrestricted discovery across the organisation.
Scope additions, extensions, approvals, evidence admission and revocation remain part of the record.
The record is a ledger, not a database: entries are added, never edited or deleted. Source identifiers, versions, timestamps, hashes and custody events travel with the evidence, so nothing can be quietly changed.
The security posture, in one line
Security review
Review deployment, identity, evidence boundaries, retention and audit requirements with the team.