Security
Data security
If you fall under NIS2, or are simply vetting a supplier, this is the page you need. Every statement here is verifiable. At the end there is a section on what we do not yet have — because the questionnaire you are filling in asks about that too.
Last revised: 6 August 2026
1. What this document is
A description of the measures in force today. It is not a certificate and does not pretend to be one. If you need a signed answer to a specific questionnaire, write to us — we complete and sign it. If you need a data processing agreement, it is on the Data processing page.
2. Where the data is
Accounts, organisations, enquiries and the data in your applications are stored in the European Union — the platform region is Frankfurt, Germany. Language model processing is the exception: the text you submit for processing goes to the model provider and may be processed outside the European Economic Area. Such transfers rest on the European Commission's standard contractual clauses.
3. Transmission and storage
- Every connection to the site and to the application is over TLS. There is no unencrypted channel.
- Passwords are stored only as an irreversible digest (scrypt) with a per-account salt. Nobody here can read your password, including if they ask.
- Email confirmation and password reset tokens are kept as a SHA-256 digest, not in readable form, and expire.
- Payment card data does not pass through our systems. Payment happens on a Stripe page.
- The database is operated by the infrastructure provider, with automated backups.
4. Who has access
Access is separated by role and checked on every request, not only at sign-in:
- A user sees only the organisations they belong to, and only what their role allows.
- Individual customers’ data is logically isolated — each customer has their own project on the platform.
- Operator access is separate from user access, on a separate address that is published nowhere on the site.
- Every operator action is written to a log: who, what, when and against which record. The log cannot be deleted from the interface.
5. Protection of the public forms
The site forms carry a submission limit per address, a hidden field against automated filling and a check on the time taken to fill them in. Suspicious submissions are kept with a flag rather than rejected — a stored false positive can be corrected, a discarded customer does not come back.
6. Sub-processors
We use an AI infrastructure and hosting provider, language model providers (OpenAI, Anthropic, Google), Stripe for payments and an email service provider. The full current list with names is provided on request by email. When a sub-processor that handles personal data changes, we notify affected customers at least 14 days in advance.
7. In an incident
We notify affected customers without undue delay and no later than 72 hours after we become aware of the incident. The notice states what happened, which data is affected, the likely consequences and what we are doing. One clarification you will not find elsewhere: for an incident in the infrastructure provider's systems, our clock starts when they notify us. We cannot promise you a shorter deadline than the one we hold upstream.
8. What we do not yet have
This section is here on purpose. If you are completing a questionnaire, these lines will save you correspondence and save us a false declaration:
- We hold no certification of our own. ISO/IEC 27001 and SOC 2 belong to the cloud provider, not to us. We do not present ourselves as certified.
- We have no two-factor authentication for user accounts. It is planned; today it does not exist.
- We have no round-the-clock security operations centre and offer no contractual response time.
- We have no independent penetration test report.
- We have no appointed data protection officer. At our processing volume the law does not require one; if your internal rules do, say so before the contract.
9. If you are regulated under NIS2
We are not an entity in scope of the NIS2 directive, but we can be your supplier, and then the duty to vet us is yours. We are ready to complete your questionnaire, sign a data processing agreement and take on contractual incident notification duties. What we cannot do is take on an obligation we do not ourselves hold towards our provider — we say so up front, not at the first audit. What you inherit from the infrastructure, and what stays yours under the AI Act, is on the NIS2 and AI Act compliance page.
10. How to reach us
For security questions, to have a questionnaire completed, or to report a vulnerability, write to the official email on the Company page. A vulnerability report is treated as a priority and we will not pursue a good-faith reporter.