Skip to content
deveca GRC
Security and privacy

Security we can prove.

Full transparency on hosting, encryption, identities, backups and audit activity — without marketing filler.

Hosting and data residency

  • Primary data centre in Nuremberg, ISO 27001 certified
  • Database at Hetzner in Nuremberg
  • Backup data centre in Falkenstein, geographically separate
  • German data residency · hosted in the EU
  • Vendor and subprocessor review against documented sovereignty criteria

Encryption

  • Data at rest: AES-256-GCM
  • Per-tenant encryption keys
  • Transport: TLS 1.3 (HSTS preloaded, OCSP stapling)
  • HSM / customer-managed KMS keys (Enterprise, on request)

Identity and access

  • RBAC with field-level rights
  • MFA enforceable for every account (TOTP, WebAuthn)
  • Session management with an audit trail
  • SSO with Microsoft Entra ID
  • Further IdPs (SAML 2.0, OIDC, Google Workspace, LDAP) — in active development

Application security

  • OWASP Top 10 as the minimum in the SDLC
  • Static and dynamic code analysis in every pipeline
  • Dependency scanning and SBOM (CycloneDX) for every release
  • Responsible disclosure for external security researchers

Operational security

  • 24/7 monitoring with a German on-call team
  • Backup strategy: 3-2-1 rule, 35 days retention
  • Disaster recovery tested (RPO 1h / RTO 4h)
  • Complete audit log of every administrative action

Compliance and contracts

  • Data processing agreement under Art. 28 GDPR
  • TOMs under Art. 32 GDPR and BSI IT-Grundschutz
  • Subprocessor list published
  • Responsible disclosure at security@deveca.de

Found a vulnerability?

We welcome every responsible report. Please encrypt your email with our PGP key (on request) and give us 90 days before you publish details.

An external penetration test by a specialist firm is planned for the next release phase; the executive summary will be published here when it is done.

security@deveca.org