Encryption
Data at rest with AES-256-GCM and a separate key per tenant. Transport over TLS 1.3 with HSTS. HSM or customer-managed KMS keys in Enterprise on request.
Security, privacy, hosting, and sub-processors of the platform — public, current, and without a sales PDF.
This Trust Center describes how deveca GRC operates the platform: where data sits, which safeguards apply, and which processors are involved. It covers the application on grc.deveca.app.
Technical and organisational measures for confidentiality, integrity, and availability. More detail is also on the security page.
Data at rest with AES-256-GCM and a separate key per tenant. Transport over TLS 1.3 with HSTS. HSM or customer-managed KMS keys in Enterprise on request.
Each tenant has its own encryption keys. No shared caches and no cross-tenant queries.
RBAC with field-level rights, enforceable MFA (TOTP, WebAuthn), and session management with an audit trail. SSO with Microsoft Entra ID is available; further IdPs (SAML, OIDC, Google Workspace, LDAP) will follow.
OWASP Top 10 as the minimum SDLC standard, static and dynamic analysis in every pipeline, plus dependency scanning and an SBOM (CycloneDX) per release.
24/7 monitoring with a German on-call rota. Backups follow the 3-2-1 rule and are kept for 35 days. Disaster recovery is tested (RPO 1h / RTO 4h).
A complete audit log of every administrative action. Responsible disclosure at security@deveca.org.
The GRC platform is developed in Germany. Runtime is at Railway, the database at Hetzner in Nuremberg, backups in Falkenstein.
Product, operations, and support are based in Germany. No offshore development for the core of the platform.
The frontend and backend of the GRC application run at Railway Corporation.
The GRC application database is hosted at Hetzner in Nuremberg.
Stored GRC data and the database at Hetzner in Nuremberg. ISO 27001-certified infrastructure, hosted in the EU, German data residency.
A geographically separate backup site in Falkenstein for recovery and resilience — also in Germany.
The marketing website may be delivered via EU or US providers. Personal customer data of the GRC application stays in the German locations named above.
Processors under Art. 28 GDPR that process personal data on behalf of deveca. Corresponding contracts exist with every provider listed.
| Provider | Purpose | Location | Safeguards |
|---|---|---|---|
Railway Corporation Privacy notice | Runtime of the GRC application (frontend and backend) | USA / EU | DPA under Art. 28 GDPR · SCC |
Hetzner Online GmbH Privacy notice | Database and object storage for evidence, attachments, and backups | Germany (Nuremberg, Falkenstein) | DPA under Art. 28 GDPR · ISO 27001 data centre · data residency DE |
Vercel Inc. Privacy notice | Hosting of the marketing website | USA / EU (fra1) | DPA · EU region for the website · DPF / SCC |
Cloudflare Inc. Privacy notice | DNS, CDN, DDoS protection, and WAF | USA / EU | DPA · SCC · EU processing where available |
Resend Inc. Privacy notice | Transactional email delivery | USA | DPA · SCC |
Stripe, Inc. Optional Privacy notice | Payment processing and subscriptions | USA / EU | DPA · PCI-DSS · SCC |
We publish material changes on this page. Questions: datenschutz@deveca.org.
Data subjects can exercise their GDPR rights through the DSR portal or directly by email.
For procurement, privacy, and audit: the essential evidence and the limits, at a glance.
The data processing agreement is part of the contract — for procurement and privacy, without an extra negotiation loop.
Technical and organisational measures follow Art. 32 GDPR and BSI IT-Grundschutz.
Operations in certified infrastructure in Nuremberg, with backup in Falkenstein.
The current list of processors is public in the Trust Center and at /subprozessoren.
Vendors and sub-processors are assessed against documented sovereignty criteria — traceable for audit and procurement.
An external penetration test is planned for the next release phase. Responsible disclosure at security@deveca.org.
This Trust Center is a transparent operations overview. It does not constitute a certificate and does not replace the DPA, TOMs, or individual contract annexes.
For privacy requests, the DPA, and security evidence you can reach us directly.
Privacy
datenschutz@deveca.orgSales & DPA
kontakt@deveca.orgDPA, TOMs, and procurement documents on request.
Information on the current operating state of the platform. The contractual basis remains the DPA, the TOMs, and the privacy policy.