Security and operations
What we do, what is still in preparation and what we do not promise.
- Location
- The servers are located in a data centre in Vienna. Customer projects run as containers on these servers.
- Separation of projects
- Each customer project has its own network and fixed limits for memory, CPU time and processes. A project has no access to files of the server or to other projects.
- Encryption
- Access to websites and the customer portal uses TLS. Certificates are issued and renewed automatically.
- Backup
- The server is backed up every night. Restoring is rehearsed regularly. Copying backups to a second location is in preparation.
- Changes on the server
- Every change is recorded in a log that cannot be altered afterwards. A snapshot is taken before the change and the result is checked afterwards. Critical changes are approved by a person.
- Signing in to the customer portal
- You sign in with a link sent by email or with a passkey. There are no passwords. Roles separate owner, billing, technical and read-only access.
- Your data is yours
- The data export is available in the customer portal from day one. We do not charge a switching fee.
- The assistant in the chat
- The help chat is an AI assistant. It reads prices and the data of your account and prepares changes. Nothing is carried out until you confirm. Answers may contain errors.
What we do not promise
- No system is invulnerable. We do not promise that either.
- We currently hold no certification such as ISO 27001.
- The legal texts, including the data processing agreement and the availability commitments, are drafts and under legal review.
Report a vulnerability
Found a vulnerability? Write to us via the request form or to the address in our security.txt. Report illegal content via “Report abuse”.