We are live · Workspace and Law pricing available
Optimaite
Trust Center

Security & Compliance

Optimaite is hosted in the EU, GDPR-compliant, and protects your data with industry-leading security measures. Transparency matters to us.

Hosted in Germany
AES-256 Encryption
GDPR-compliant
No AI training with your data

Compliance

Our platform meets the strict requirements of European data protection and security standards.

GDPR

Full compliance with the European General Data Protection Regulation. DPA, TOMs, and subprocessor registry available.

Compliant

EU Hosting

All application data is exclusively processed and stored in the EU. Infrastructure at Hetzner Cloud in Germany.

Germany

No AI Training

Your data is never used to train AI models. AI processing takes place in EU data centres via Microsoft Azure AI Foundry (Germany), AWS Bedrock (Frankfurt) and Google Vertex AI (EU) with zero-retention agreements; third-country involvement is safeguarded by adequacy decisions or EU Standard Contractual Clauses.

Guaranteed

Security Measures

Technical and organizational measures to protect your data.

Infrastructure

12 Controls
  • Encryption in transit (TLS 1.3) and at rest (AES-256)
  • Kubernetes cluster with network segmentation
  • Automatic backups with point-in-time recovery
Show all

Access Control

8 Controls
  • Multi-tenant isolation at database level
  • JWT-based authentication with tenant scoping
  • Role-based access control (RBAC)
Show all

Data Privacy

10 Controls
  • Data processing exclusively in the EU
  • Automatic data deletion at contract end
  • Data classification and retention policies
Show all

Organization

9 Controls
  • Regular security training for all employees
  • Incident response plan documented and tested
  • Confidentiality agreements with all employees
Show all

Data Processing

How your data flows through our platform and where it is processed.

Infrastructure

Kubernetes ClusterHetzner Cloud, Falkenstein/Nürnberg, DE
DatabaseSelf-hosted PostgreSQL (CloudNativePG), Hetzner, DE
Object StorageHetzner S3-compatible, Falkenstein, DE
Website & EdgeVercel, EU regions

Processed Data

Name & email address

User accounts & authentication

Documents & files

Document processing, AI analysis

Chat messages

AI assistance & communication

IP addresses & metadata

Security logging & error diagnostics

Subprocessors

Show all
H

Hetzner Cloud

Infrastructure & storage · Germany

Z

Zilliz Cloud

Vector database (embeddings) · EU (Frankfurt)

A

Azure AI

AI provider (GPT, Gemini) · EU (Germany)

A

AWS Bedrock

AI provider (Claude) · EU (Frankfurt)

V

Vercel

Website hosting · EU regions

S

Sentry

Error monitoring · EU

Legal Documents

All relevant documents for your compliance review.

Frequently Asked Questions

Where is my data hosted?

All application data is processed and stored exclusively in Germany (Hetzner Cloud, Falkenstein/Nürnberg) in EU data centres. AI processing takes place via EU-based services (Microsoft Azure AI Foundry – Germany, AWS Bedrock – Frankfurt, Google Vertex AI – EU); any third-country involvement is safeguarded by adequacy decisions or EU Standard Contractual Clauses.

Are AI models trained on my data?

No. We operate AI models through EU-based services (Microsoft Azure AI Foundry in Germany, AWS Bedrock in Frankfurt, Google Vertex AI in the EU) with explicit zero-retention and zero-training agreements. Customer data is processed in EU data centres in regular cloud operation and discarded immediately after processing; any third-country involvement is safeguarded by adequacy decisions or EU Standard Contractual Clauses.

Do you offer a Data Processing Agreement (DPA)?

Yes. Our DPA pursuant to Art. 28 GDPR is available as part of our terms of service and includes the technical and organizational measures (TOMs) as well as the complete subprocessor registry.

How is tenant isolation ensured?

Optimaite implements a strict multi-tenant architecture with isolation at the database level. Every tenant query is automatically filtered, preventing unauthorized access to other tenants' data.

Questions about security & compliance?

Our team is happy to assist you with security questions, DPA requests, and compliance reviews.