Security and data protection
Your data stays in the EU, on machines we run ourselves.
Security reviews want specifics, so this page gives them: where the data physically sits, what protects it, and what we sign. Every line here is something a reviewer can ask us to demonstrate.
- Where
- Germany
- Our own server, in a German data centre
- Transport
- TLS only
- Certificates rotated automatically
- Agreement
- DPA
- Signed together with the contract
Where the data lives
Physical location first, brand names second.
The server is in Germany
The applications and this site run on our own server in a German data centre. We administer it ourselves rather than renting space on somebody else's panel, so nothing about the configuration is a mystery to us.
Processing stays in the EU
The database, the files and the backups sit on European infrastructure. Where a product has to call an external service to do its job, we will tell you which one and where it runs.
Nothing leaves the EU in normal operation
No routine transfer to a third country, and no copy of your data kept anywhere we have not told you about. If that ever has to change for a feature you asked for, you hear it before it happens.
How it is protected
Four things, described precisely.
Written the way a reviewer would want to verify them, rather than as a list of nouns.
- Encrypted transport, everywhere, renewed automatically
- Every hostname is served over TLS by the reverse proxy, which issues and rotates certificates on its own schedule. No plain HTTP endpoint is exposed; requests on port 80 are redirected before anything is served.
- The firewall opens three ports and nothing else
- Inbound traffic reaches port 80 and 443 for the web, and SSH. Everything else is dropped at the host. SSH is rate limited, so a password guessing run gets throttled rather than logged and ignored.
- Administrative access is by key, and root cannot log in
- Direct root login over SSH is refused. Administrators connect with their own key to their own account and use elevated rights per command, which leaves a trail instead of a shared login.
- Application services do not listen to the internet
- Product back ends bind to the loopback interface and are reachable only through the reverse proxy. There is no port you can hit directly, which is why the firewall list above is as short as it is.
What we commit to
GDPR, without the annex.
We are a European company building for European buyers, so this is an obligation rather than a feature. Six commitments, in the words we would use on a call.
- 01
You are the controller, we are the processor
The data you put into our products stays yours. We process it to run the service you bought and for nothing else: no resale, no shared enrichment database built from your records, no using your content to train models.
- 02
A data processing agreement is signed with the contract
Ours or yours, whichever your legal team prefers. It is part of signing, not a document you chase in month two.
- 03
Access, export, correction and deletion
Ask and you get a machine readable export, in practice the same week and at the latest within 30 days. Deletion removes the record and everything derived from it, including scores and signals, not only the ability to log in.
- 04
You get the full list of who else processes the data
Every sub-processor, with its region and what it does, sent with the DPA. If that list changes you hear about it before the change takes effect, with time to object.
- 05
Breach notification inside 72 hours
To you and to the regulator, from one named person rather than a queue. You get what happened, what we know, and what we do not know yet.
- 06
Reading a proposal is personal data, and we treat it that way
propoSEND records how an offer is read. Company level reading rests on legitimate interest. Naming an individual reader rests on that person identifying themselves to open the document, which is a cleaner basis than matching cookies to IP addresses, and it is disclosed in the document window rather than buried in terms.
Certifications
What we can send you today.
A completed vendor security questionnaire, in writing, inside two working days.
What we cannot send is a SOC 2 report or an ISO 27001 certificate, because those are produced by an auditor over an observation window and we have not been through one. You will not find those words next to a badge anywhere on this site. If your process requires a completed audit today, we would rather you learn that here than in week six of an evaluation.
Security questions
Send the questionnaire.
Your standard vendor form, your DPA template, or just the three questions your security team always asks. Two working days, from a named person, with the honest answer where the answer is no.