Security and privacy
Security we can prove.
Full transparency on hosting, encryption, identities, backups and audit activity — without marketing filler.
Hosting and data residency
- Primary data centre in Nuremberg, ISO 27001 certified
- Database at Hetzner in Nuremberg
- Backup data centre in Falkenstein, geographically separate
- German data residency · hosted in the EU
- Vendor and subprocessor review against documented sovereignty criteria
Encryption
- Data at rest: AES-256-GCM
- Per-tenant encryption keys
- Transport: TLS 1.3 (HSTS preloaded, OCSP stapling)
- HSM / customer-managed KMS keys (Enterprise, on request)
Identity and access
- RBAC with field-level rights
- MFA enforceable for every account (TOTP, WebAuthn)
- Session management with an audit trail
- SSO with Microsoft Entra ID
- Further IdPs (SAML 2.0, OIDC, Google Workspace, LDAP) — in active development
Application security
- OWASP Top 10 as the minimum in the SDLC
- Static and dynamic code analysis in every pipeline
- Dependency scanning and SBOM (CycloneDX) for every release
- Responsible disclosure for external security researchers
Operational security
- 24/7 monitoring with a German on-call team
- Backup strategy: 3-2-1 rule, 35 days retention
- Disaster recovery tested (RPO 1h / RTO 4h)
- Complete audit log of every administrative action
Compliance and contracts
- Data processing agreement under Art. 28 GDPR
- TOMs under Art. 32 GDPR and BSI IT-Grundschutz
- Subprocessor list published
- Responsible disclosure at security@deveca.de
Found a vulnerability?
We welcome every responsible report. Please encrypt your email with our PGP key (on request) and give us 90 days before you publish details.
An external penetration test by a specialist firm is planned for the next release phase; the executive summary will be published here when it is done.
security@deveca.org