Security built into every layer
Vault-managed encryption, immutable backups, anomaly detection, and EU-only data residency — built to protect against ransomware, data loss, and compliance failures.
Ransomware attack detected
Source tenant compromised
Archive immutable — unaffected
WORM seal intact, no data modified
AES-256-GCM encryption active
Per-tenant keys via HashiCorp Vault
Recovery point available
Point-in-time restore ready, 2 min ago
Full restore initiated
Estimated time: < 3 seconds per item
RBAC
Active
Audit Log
Recording
BYOK
Enabled
EU Residency
DE / FI
AES-256-GCM
Vault-managed encryption
Immutable Backups
WORM-protected archive
EU Residency
Germany (primary) & Finland (secondary)
Backup Shield
Anomaly detection
Encryption
Vault-managed encryption at every level
All encryption keys are managed by HashiCorp Vault Transit and zeroed from memory after use.
AES-256-GCM encryption at rest
Every archived item is encrypted with AES-256-GCM inside the platform, before it reaches storage. Keys are managed per tenant through the HashiCorp Vault Transit engine.
- Client-side encryption with a separate key per tenant — the storage provider only ever sees ciphertext
- Automatic key rotation via Vault Transit
- SecureBuffer: encryption keys are zeroed from memory after cryptographic operations
- Compressed (gzip) before encryption for storage efficiency
Bring Your Own Key (BYOK)
Maintain complete control with envelope encryption. Your master key encrypts the data encryption key (DEK) — revoke it at any time to make data permanently inaccessible.
- A separate data key per object, wrapped by your own key
- Your master key never leaves your control
- Revoke the key to make all archived data inaccessible
- Compatible with any key vault that supports AES-256
Envelope encryption flow
Every object is encrypted with its own data key. That key is wrapped by your tenant object key, which in turn is wrapped by a per-tenant key that never leaves Vault Transit. Supply your own object key and the chain is rooted in material we cannot regenerate.
Ransomware Protection
Immutable backups, real-time anomaly detection
Your archive is write-once and integrity-verified. Backup Shield detects suspicious activity before damage spreads.
Backup Shield anomaly detection
Six independent detection signals monitor every backup run — behavioral baselines, content analysis, and a curated ransomware IOC feed. Corroborated freezing prevents compromised data from overwriting clean backups without false-alarm lockups.
- Detects mass deletion, mass encryption, volume spikes, and entropy anomalies
- Ransomware IOC matching: 100+ known file extensions and ransom-note filename patterns
- Corroborated auto-freeze: critical findings, or two independent signal families in agreement
- Cross-mailbox correlation flags tenant-wide attacks; Clean Score tracks health per run
Immutable archive (WORM)
Write-once, read-many storage with cryptographic hash chains. Once sealed, archive data is protected against modification and deletion by database-level triggers — including application-level administrator actions.
- SHA-256 hash chains verify data integrity
- SEAL_PENDING → SEALED lifecycle with retention policies
- Automated integrity verification (VERIFY_HASHES)
- Configurable retention periods with legal hold support
Shield Replication
Clean backup runs are automatically replicated to geographically separate S3 storage, ensuring recovery even if primary storage is compromised.
- Automatic replication of verified-clean backups every 30 minutes
- Secondary S3 storage in separate location
- Only CLEAN runs are replicated — compromised data stays isolated
- Geographic redundancy within the EU
Point-in-time recovery
Granular restore from any backup point in the version history. Recover individual items or entire mailboxes to any previous state.
- Version history for every backed-up item
- Item-level and mailbox-level restore
- Restore directly to M365 or download as archive
- Typical restore time under 3 seconds per item (depends on item size and M365 API conditions)
Data Residency
Your data stays in the EU
All data is stored and processed exclusively in European Union data centers. No US-based sub-processors are used for customer data storage or processing. DNS and TLS certificate management use Cloudflare, which does not access or store customer data.
- Primary storage in Germany, secondary storage in Finland
- k3s cluster with dedicated data nodes in EU
- No data transfer outside the European Union
- German company under German/EU jurisdiction
- Shield Replication to secondary region (Finland)
European Union
S3 Object Storage, Germany
European Union
S3 Object Storage, Finland
Access Control
Granular permissions, complete audit trail
Four system roles with 20+ permissions ensure least-privilege access. Every action is logged to both PostgreSQL and OpenSearch for searchable audit trails.
Role-based access control (RBAC)
Four system roles — Owner, Admin, Member, ReadOnly — with 20+ granular permissions covering tenants, users, providers, backups, restores, search, billing, audit, and compliance.
- Permissions cached in Redis (5-minute TTL) for performance
- Tenant-level isolation — users only see their own tenant data
- Principle of least privilege enforced at middleware level
- Custom permission checks on every API endpoint
Dual-write audit logging
Every administrative action, data access, and security event is logged to both PostgreSQL (durable) and OpenSearch (searchable) via Redis Streams.
- Structured audit events with actor, action, resource, and metadata
- Full-text searchable audit trail via OpenSearch
- Exportable logs for compliance reviews and incident response
- Real-time event streaming for monitoring integration
Compliance & Transparency
Verifiable, not just claimed
We publish our DPA, technical measures, and vulnerability disclosure policy. Review our security posture before you commit.
GDPR compliance
EU-based company with EU-only data storage. Full data subject rights support, consent management, and GDPR-compliant data processing.
Data Processing Agreement
Published DPA per Art. 28 GDPR covering 13 sections: sub-processors, data subject rights, technical measures, breach notification, and audit rights.
Read documentTechnical & organizational measures
Art. 32 GDPR TOM document detailing encryption standards, access controls, backup procedures, and incident response processes.
Read documentVulnerability disclosure policy
Public responsible disclosure program with defined scope. 48-hour acknowledgment SLA and 7-day investigation commitment for reported vulnerabilities.
Read documentMulti-tenant isolation
Database-level tenant isolation via Prisma extension with AsyncLocalStorage. 26+ models auto-filtered by tenant ID — cross-tenant data access prevented by design.
NIS2 alignment
EU-hosted infrastructure, comprehensive audit logging, incident response procedures, and encryption standards align with NIS2 directive requirements for essential entities.
Security you can verify
Read our DPA, review our vulnerability disclosure policy, check our technical measures. Immutable backups, Vault-managed encryption, and Backup Shield anomaly detection — all verifiable.
