What we do, and what we do not.
No seal and no diagram, but the five things that actually happen in operation, each named precisely enough for you to ask about it.
What happens in operation
The keys to your AI provider, your repository and the embedding service sit encrypted in the database, not in plain text. Whoever had the database would still have no access to your other systems.
Database and attachments separately, daily, onto another system. The backups are encrypted, and only the public key lives on the server: a compromised server can create backups but cannot read them.
The separation sits in every database query, not in the interface. A task belongs to exactly one project, a project to exactly one organisation, and there is no path around it.
What you delete disappears from the backups too, once their retention has run out. Every deletion is recorded, so you can prove it when your client asks.
What we do not do
Three things security pages like to claim, and which are not claimed here.
- No end-to-end encryption of content. Your tasks and documents sit readable in the database, otherwise neither search nor AI could work with them. Encrypted are the credentials and the backups, and that is what this says instead of a blanket "everything is encrypted".
- No data centre of our own. We rent from a German provider and say so, rather than speaking of "our infrastructure".
- No ISO 27001 certification. What we do is on this page and in your data processing agreement, not in a seal.
What people ask at this point
- Who on your side can see my data?
- For operations, the founder, and then only when maintenance or an incident requires it. There is no team reading along, because there is no such team. What is allowed and what is not is in your data processing agreement.
- What happens if the server fails?
- Last night's state is restored. Several weeks of backups are kept, not just yesterday's, so a mistake noticed later has not already been overwritten.
- And if something does go wrong?
- Then you hear about it. The reporting paths for a data breach are prescribed by law and set out in your contract; we follow them, including when it is uncomfortable.
Where the data sits is a question of its own.
Jurisdiction, AI provider and what your contract says are answered by the data sovereignty page. What the application stores in detail is in the privacy policy.