Trust & security

How we protect your data — our security posture, the subprocessors we rely on, where data is hosted, and how to report a vulnerability. Operated by Zenith Yield GmbH.

Security posture

Authentication & access
Multi-factor authentication (TOTP) with recovery codes, passkeys (WebAuthn), and per-organisation single sign-on (OIDC) with SCIM user provisioning and deprovisioning.
Encryption in transit
All traffic is encrypted in transit with TLS, terminated at the edge and reinforced by in-app security response headers (HSTS, CSP and more).
Encryption at rest
Database backups are encrypted with AES-256 (GPG), and documents and exports in object storage are encrypted at rest (server-side, AES-256). The database and cache volumes rely on the host provider's disk encryption where enabled in your deployment.
Multi-tenant isolation
Each organisation's data is isolated: every query is organisation-scoped and enforced at the database layer with Postgres row-level security.
Secure development & scanning
Every change passes automated security gates in CI: static analysis (Semgrep SAST), secret scanning, container vulnerability scanning, and continuous dependency updates.
Audit log & data rights
Security-relevant actions are recorded in an append-only audit log. You can export your data and request its erasure in line with the GDPR.

Subprocessors

The third-party services we rely on to operate the platform: the personal-data categories each may process, where it is hosted, and the transfer basis when data leaves the EEA. A data-processing agreement (DPA) is signed with each subprocessor that requires one before production use.

SubprocessorPurposeData categoriesHostingTransferDPA
ResendTransactional + marketing email delivery (prod transport)Account identityContact detailsUSDPF / SCCRequired
StripeBilling, subscriptions, checkout/portalBillingContact detailsUS (EU region available)DPF / SCCRequired
SentryError monitoring + performance tracesError diagnosticsNetwork metadataAccount identityUS (EU region available)DPF / SCCRequired
PostHogProduct analyticsUsage analyticsNetwork metadataEU / EEANone (EEA)Required
Object storage (S3-compatible)Stores uploaded documents, generated PDFs, and GDPR data exportsDocuments & filesSupport contentOperator-chosenOperator to determineRequired
Preview CDN (signed private edge)Speeds up document previews via an edge cacheDocuments & filesOperator-chosenOperator to determineRequired
Google MapsMap and location visualisationNetwork metadataUSDPF / SCCRequired
MapboxMap / geo visualisation (alternative tiles)Network metadataUSDPF / SCCRequired
Cal.comBook-an-expert schedulingContact detailsOperator-chosenDPF / SCCRequired
GitHubSupport-request trackingSupport contentUSDPF / SCCRequired
CloudflareEdge proxy, DNS, tunnel, WAFNetwork metadataGlobal (CDN)DPF / SCCRequired
InfisicalSecrets managementNo personal dataEU / EEANone (EEA)Required
Hosting providerApplication hosting and primary data storageAccount identityContact detailsDocuments & filesSupport contentBillingNetwork metadataOperator-chosenOperator to determineRequired
VercelSoftware build cacheNo personal dataUSN/A (no personal data)
TailscaleSecure private network for staff administrative accessNetwork metadataUSDPF / SCC
Google CloudAI-assisted document readingDocuments & filesContact detailsUS (EU region available)DPF / SCCRequired
Amazon Web ServicesAI-assisted document readingDocuments & filesContact detailsUS (EU region available)DPF / SCCRequired
Microsoft AzureAI-assisted document readingDocuments & filesContact detailsUS (EU region available)DPF / SCCRequired
DATEVDelivery of documents to your accounting systemDocuments & filesContact detailsEU / EEANone (EEA)Required

Data residency

Our primary datastore runs on deployment infrastructure in the European Economic Area (EEA), in Germany by default. Where a subprocessor offers an EU region we choose it by default — for example product analytics and secrets management. Some subprocessors are US-based, as shown in the table below.

Where a subprocessor is hosted outside the EEA, the transfer relies on the EU–US Data Privacy Framework and/or the EU Standard Contractual Clauses, and we minimise the personal data shared.

Report a vulnerability

Found a security issue? Please report it privately — do not open a public issue — and give us a reasonable window to remediate before any public disclosure. We aim to acknowledge within two business days. Our full disclosure policy and scope live in the repository's SECURITY.md.