Trust Center
What your security team wants to know before sign-off.
Hosting, encryption, subprocessors, exit. The DPA is available as a PDF — no form.
01
Data processing
The model DPA is available without registration. No field between you and the contract.
02
Operations and security
Hosting and data location
Data centre Germany
Operator ISO 27001-certified
Third-country transfer none
Certifications and status
ISO 27001 in preparation · target quarter open
C5 architecture aligned to C5
Evidence on request
Encryption
In transit TLS 1.3
At rest AES-256
Key management separate from the data set
Availability and backup
SLA standard 99.5%
Backup daily, 30-day retention
Restore test regular, logged
Access and role model
Authentication Keycloak, SSO possible
Role model role-based per tenant
Tenant separation logically separated
Exit and data portability
Export complete, to Excel
Notice any time, no request
Deletion policy documented
03
Subprocessors
| Provider | Purpose | Location | Legal basis |
|---|---|---|---|
| Data centre operator | Hosting | Germany | DPA |
| Email delivery | System notifications | EU | DPA |
| Error monitoring | Operations | EU | DPA |
Placeholder: insert actual provider names only after sign-off by data protection and operations.
04
Report a vulnerability
We treat reports of security flaws confidentially and acknowledge receipt within one business day.
[email protected] · PGP on request
05
30 minutes, your standards, your scope.
✓No sales pitch
✓A demo on your use case, not on sample data
✓Reply within one business day
✓Your data is never passed to third parties