Skip to content
deveca GRC
Trust Center

Transparency you can audit.

Security, privacy, hosting, and sub-processors of the platform — public, current, and without a sales PDF.

Developed in GermanyData residency Nuremberg · backup FalkensteinAs of: 15 September 2026

Overview

This Trust Center describes how deveca GRC operates the platform: where data sits, which safeguards apply, and which processors are involved. It covers the application on grc.deveca.app.

Security

Technical and organisational measures for confidentiality, integrity, and availability. More detail is also on the security page.

Encryption

Data at rest with AES-256-GCM and a separate key per tenant. Transport over TLS 1.3 with HSTS. HSM or customer-managed KMS keys in Enterprise on request.

Tenant isolation

Each tenant has its own encryption keys. No shared caches and no cross-tenant queries.

Identity & access

RBAC with field-level rights, enforceable MFA (TOTP, WebAuthn), and session management with an audit trail. SSO with Microsoft Entra ID is available; further IdPs (SAML, OIDC, Google Workspace, LDAP) will follow.

Application security

OWASP Top 10 as the minimum SDLC standard, static and dynamic analysis in every pipeline, plus dependency scanning and an SBOM (CycloneDX) per release.

Operations & recovery

24/7 monitoring with a German on-call rota. Backups follow the 3-2-1 rule and are kept for 35 days. Disaster recovery is tested (RPO 1h / RTO 4h).

Logging

A complete audit log of every administrative action. Responsible disclosure at security@deveca.org.

Hosting & data residency

The GRC platform is developed in Germany. Runtime is at Railway, the database at Hetzner in Nuremberg, backups in Falkenstein.

Development in Germany

Product, operations, and support are based in Germany. No offshore development for the core of the platform.

Runtime

Railway

The frontend and backend of the GRC application run at Railway Corporation.

Database

Hetzner

The GRC application database is hosted at Hetzner in Nuremberg.

Primary data centre

Nürnberg

Stored GRC data and the database at Hetzner in Nuremberg. ISO 27001-certified infrastructure, hosted in the EU, German data residency.

Backup data centre

Falkenstein

A geographically separate backup site in Falkenstein for recovery and resilience — also in Germany.

The marketing website may be delivered via EU or US providers. Personal customer data of the GRC application stays in the German locations named above.

Sub-processors

Processors under Art. 28 GDPR that process personal data on behalf of deveca. Corresponding contracts exist with every provider listed.

ProviderPurposeLocationSafeguards

Railway Corporation

Privacy notice
Runtime of the GRC application (frontend and backend)USA / EUDPA under Art. 28 GDPR · SCC

Hetzner Online GmbH

Privacy notice
Database and object storage for evidence, attachments, and backupsGermany (Nuremberg, Falkenstein)DPA under Art. 28 GDPR · ISO 27001 data centre · data residency DE

Vercel Inc.

Privacy notice
Hosting of the marketing websiteUSA / EU (fra1)DPA · EU region for the website · DPF / SCC

Cloudflare Inc.

Privacy notice
DNS, CDN, DDoS protection, and WAFUSA / EUDPA · SCC · EU processing where available

Resend Inc.

Privacy notice
Transactional email deliveryUSADPA · SCC

Stripe, Inc.

Optional

Privacy notice
Payment processing and subscriptionsUSA / EUDPA · PCI-DSS · SCC

We publish material changes on this page. Questions: datenschutz@deveca.org.

Privacy

Data subjects can exercise their GDPR rights through the DSR portal or directly by email.

  • Access to stored personal data
  • Rectification of inaccurate data
  • Erasure where legally permitted
  • Data portability in a common format
  • Objection to certain processing
  • Complaint to a supervisory authority

Compliance

For procurement, privacy, and audit: the essential evidence and the limits, at a glance.

DPA under Art. 28 GDPR

The data processing agreement is part of the contract — for procurement and privacy, without an extra negotiation loop.

TOMs under Art. 32 GDPR

Technical and organisational measures follow Art. 32 GDPR and BSI IT-Grundschutz.

ISO 27001 data centre

Operations in certified infrastructure in Nuremberg, with backup in Falkenstein.

Sub-processor transparency

The current list of processors is public in the Trust Center and at /subprozessoren.

German data residency

Vendors and sub-processors are assessed against documented sovereignty criteria — traceable for audit and procurement.

Pentest & disclosure

An external penetration test is planned for the next release phase. Responsible disclosure at security@deveca.org.

This Trust Center is a transparent operations overview. It does not constitute a certificate and does not replace the DPA, TOMs, or individual contract annexes.

Contact

For privacy requests, the DPA, and security evidence you can reach us directly.

Information on the current operating state of the platform. The contractual basis remains the DPA, the TOMs, and the privacy policy.