Cookie Settings

We use cookies to ensure the basic functionality of our website. Essential cookies (theme preference, session, consent status) are required and cannot be disabled. Optional cookies for analytics and payment processing are only set with your explicit consent. Privacy Policy

Security built into every layer

Vault-managed encryption, immutable backups, anomaly detection, and EU-only data residency — built to protect against ransomware, data loss, and compliance failures.

Security Console
All systems protected
Encryption: AES-256Region: EU
!

Ransomware attack detected

Source tenant compromised

Archive immutable — unaffected

WORM seal intact, no data modified

AES-256-GCM encryption active

Per-tenant keys via HashiCorp Vault

Recovery point available

Point-in-time restore ready, 2 min ago

Full restore initiated

Estimated time: < 3 seconds per item

RBAC

Active

Audit Log

Recording

BYOK

Enabled

EU Residency

DE / FI

AES-256-GCM

Vault-managed encryption

Immutable Backups

WORM-protected archive

EU Residency

Germany (primary) & Finland (secondary)

Backup Shield

Anomaly detection

Encryption

Vault-managed encryption at every level

All encryption keys are managed by HashiCorp Vault Transit and zeroed from memory after use.

AES-256-GCM encryption at rest

Every archived item is encrypted with AES-256-GCM inside the platform, before it reaches storage. Keys are managed per tenant through the HashiCorp Vault Transit engine.

  • Client-side encryption with a separate key per tenant — the storage provider only ever sees ciphertext
  • Automatic key rotation via Vault Transit
  • SecureBuffer: encryption keys are zeroed from memory after cryptographic operations
  • Compressed (gzip) before encryption for storage efficiency

Bring Your Own Key (BYOK)

Maintain complete control with envelope encryption. Your master key encrypts the data encryption key (DEK) — revoke it at any time to make data permanently inaccessible.

  • A separate data key per object, wrapped by your own key
  • Your master key never leaves your control
  • Revoke the key to make all archived data inaccessible
  • Compatible with any key vault that supports AES-256

Envelope encryption flow

Every object is encrypted with its own data key. That key is wrapped by your tenant object key, which in turn is wrapped by a per-tenant key that never leaves Vault Transit. Supply your own object key and the chain is rooted in material we cannot regenerate.

Vault TransitPer-Tenant KeysAuto-RotationBYOK

Ransomware Protection

Immutable backups, real-time anomaly detection

Your archive is write-once and integrity-verified. Backup Shield detects suspicious activity before damage spreads.

Backup Shield anomaly detection

Six independent detection signals monitor every backup run — behavioral baselines, content analysis, and a curated ransomware IOC feed. Corroborated freezing prevents compromised data from overwriting clean backups without false-alarm lockups.

  • Detects mass deletion, mass encryption, volume spikes, and entropy anomalies
  • Ransomware IOC matching: 100+ known file extensions and ransom-note filename patterns
  • Corroborated auto-freeze: critical findings, or two independent signal families in agreement
  • Cross-mailbox correlation flags tenant-wide attacks; Clean Score tracks health per run

Immutable archive (WORM)

Write-once, read-many storage with cryptographic hash chains. Once sealed, archive data is protected against modification and deletion by database-level triggers — including application-level administrator actions.

  • SHA-256 hash chains verify data integrity
  • SEAL_PENDING → SEALED lifecycle with retention policies
  • Automated integrity verification (VERIFY_HASHES)
  • Configurable retention periods with legal hold support

Shield Replication

Clean backup runs are automatically replicated to geographically separate S3 storage, ensuring recovery even if primary storage is compromised.

  • Automatic replication of verified-clean backups every 30 minutes
  • Secondary S3 storage in separate location
  • Only CLEAN runs are replicated — compromised data stays isolated
  • Geographic redundancy within the EU

Point-in-time recovery

Granular restore from any backup point in the version history. Recover individual items or entire mailboxes to any previous state.

  • Version history for every backed-up item
  • Item-level and mailbox-level restore
  • Restore directly to M365 or download as archive
  • Typical restore time under 3 seconds per item (depends on item size and M365 API conditions)

Data Residency

Your data stays in the EU

All data is stored and processed exclusively in European Union data centers. No US-based sub-processors are used for customer data storage or processing. DNS and TLS certificate management use Cloudflare, which does not access or store customer data.

  • Primary storage in Germany, secondary storage in Finland
  • k3s cluster with dedicated data nodes in EU
  • No data transfer outside the European Union
  • German company under German/EU jurisdiction
  • Shield Replication to secondary region (Finland)

European Union

S3 Object Storage, Germany

Primary

European Union

S3 Object Storage, Finland

Secondary

Access Control

Granular permissions, complete audit trail

Four system roles with 20+ permissions ensure least-privilege access. Every action is logged to both PostgreSQL and OpenSearch for searchable audit trails.

Role-based access control (RBAC)

Four system roles — Owner, Admin, Member, ReadOnly — with 20+ granular permissions covering tenants, users, providers, backups, restores, search, billing, audit, and compliance.

  • Permissions cached in Redis (5-minute TTL) for performance
  • Tenant-level isolation — users only see their own tenant data
  • Principle of least privilege enforced at middleware level
  • Custom permission checks on every API endpoint

Dual-write audit logging

Every administrative action, data access, and security event is logged to both PostgreSQL (durable) and OpenSearch (searchable) via Redis Streams.

  • Structured audit events with actor, action, resource, and metadata
  • Full-text searchable audit trail via OpenSearch
  • Exportable logs for compliance reviews and incident response
  • Real-time event streaming for monitoring integration

Compliance & Transparency

Verifiable, not just claimed

We publish our DPA, technical measures, and vulnerability disclosure policy. Review our security posture before you commit.

GDPR compliance

EU-based company with EU-only data storage. Full data subject rights support, consent management, and GDPR-compliant data processing.

Data Processing Agreement

Published DPA per Art. 28 GDPR covering 13 sections: sub-processors, data subject rights, technical measures, breach notification, and audit rights.

Read document

Technical & organizational measures

Art. 32 GDPR TOM document detailing encryption standards, access controls, backup procedures, and incident response processes.

Read document

Vulnerability disclosure policy

Public responsible disclosure program with defined scope. 48-hour acknowledgment SLA and 7-day investigation commitment for reported vulnerabilities.

Read document

Multi-tenant isolation

Database-level tenant isolation via Prisma extension with AsyncLocalStorage. 26+ models auto-filtered by tenant ID — cross-tenant data access prevented by design.

NIS2 alignment

EU-hosted infrastructure, comprehensive audit logging, incident response procedures, and encryption standards align with NIS2 directive requirements for essential entities.

Security you can verify

Read our DPA, review our vulnerability disclosure policy, check our technical measures. Immutable backups, Vault-managed encryption, and Backup Shield anomaly detection — all verifiable.