Optimaite Logo
Trust Center

Security & Compliance

Optimaite is hosted in the EU, GDPR-compliant, and protects your data with industry-leading security measures. Transparency matters to us.

Hosted in Germany
AES-256 Encryption
GDPR-compliant
No AI training with your data

Compliance

Our platform meets the strict requirements of European data protection and security standards.

GDPR

Full compliance with the European General Data Protection Regulation. DPA, TOMs, and subprocessor registry available.

Compliant

EU Hosting

All application data is exclusively processed and stored in the EU. Infrastructure at Hetzner Cloud in Germany.

Germany

No AI Training

Your data is never used to train AI models. All AI processing takes place exclusively within the EU via Azure AI (Germany) and AWS (Frankfurt) with zero-retention agreements.

Guaranteed

Security Measures

Technical and organizational measures to protect your data.

Infrastructure

12 Controls
  • Encryption in transit (TLS 1.3) and at rest (AES-256)
  • Kubernetes cluster with network segmentation
  • Automatic backups with point-in-time recovery
Show all

Access Control

8 Controls
  • Multi-tenant isolation at database level
  • JWT-based authentication with tenant scoping
  • Role-based access control (RBAC)
Show all

Data Privacy

10 Controls
  • Data processing exclusively in the EU
  • Automatic data deletion at contract end
  • Data classification and retention policies
Show all

Organization

9 Controls
  • Regular security training for all employees
  • Incident response plan documented and tested
  • Confidentiality agreements with all employees
Show all

Data Processing

How your data flows through our platform and where it is processed.

Infrastructure

Kubernetes ClusterHetzner Cloud, Falkenstein/Frankfurt, DE
DatabaseNeon Serverless Postgres, Frankfurt, EU
Object StorageHetzner S3-compatible, Falkenstein, DE
Website & EdgeVercel, EU regions

Processed Data

Name & email address

User accounts & authentication

Documents & files

Document processing, AI analysis

Chat messages

AI assistance & communication

IP addresses & metadata

Security logging & error diagnostics

Subprocessors

Show all
H

Hetzner Cloud

Infrastructure & storage · Germany

N

Neon

Database · EU (Frankfurt)

A

Azure AI

AI provider (GPT, Gemini) · EU (Germany)

A

AWS Bedrock

AI provider (Claude) · EU (Frankfurt)

V

Vercel

Website hosting · EU regions

S

Sentry

Error monitoring · EU

Legal Documents

All relevant documents for your compliance review.

Frequently Asked Questions

Where is my data hosted?

All application data is processed and stored in Germany (Hetzner Cloud, Falkenstein/Frankfurt) and the EU (Neon Postgres, Frankfurt). AI processing also takes place exclusively within the EU via Azure AI (Germany) and AWS Bedrock (Frankfurt).

Are AI models trained on my data?

No. We operate AI models exclusively through EU-based services (Azure AI in Germany, AWS Bedrock in Frankfurt) with explicit zero-retention and zero-training agreements. Your data never leaves the EU and is immediately discarded after processing.

Do you offer a Data Processing Agreement (DPA)?

Yes. Our DPA pursuant to Art. 28 GDPR is available as part of our terms of service and includes the technical and organizational measures (TOMs) as well as the complete subprocessor registry.

How is tenant isolation ensured?

Optimaite implements a strict multi-tenant architecture with isolation at the database level. Every tenant query is automatically filtered, making access to other tenants' data technically impossible.

Questions about security & compliance?

Our team is happy to assist you with security questions, DPA requests, and compliance reviews.

Trust Center | Optimaite