

Compliance
Infrastructure & Residency
All our systems are hosted in heavily secured Tier III+ data centers. We believe in full data sovereignty.
- All workloads run on dedicated Hetzner servers in Germany.
- All data processing fully complies with GDPR/AVG regulations.
- We have no dependency on US cloud providers (AWS/Azure).
- All data-at-rest is secured with AES-256 enterprise-grade encryption.
- Encrypted backups are stored off-site daily.
- Our infrastructure is proactively monitored 24/7.
AI Integrity
We do not use public APIs.
- Proprietary AI Engine: our own, internally managed models.
- No data-sharing with OpenAI or other external AI providers.
- Isolated Tenant Environments for strict data segregation.
- Zero-Training Guarantee: customer data is never used for model training.
Governance
Our organization breathes security.
- ISO 27001 Alignment: processes designed to international standards.
- MFA Enforcement: Multi-Factor Authentication required for all access.
- Role-Based Access Control (RBAC) for minimal rights per role.
- Incident Response Protocols: structured protocol for security incidents.
Data Privacy
Privacy by design is our standard.
- Automated PII Redaction: privacy-sensitive data is automatically filtered.
- Zero Retention Policy: data is deleted in accordance with retention periods.
- Data Minimization: we only collect what is strictly necessary.
- GDPR-Compliant Logs: audit logs meet privacy requirements.
Ecosystem Security
Verified by the largest platforms.
- Shopify Certified Integration Partner.
- Google Certified Integration Partner.
- API Security Audits successfully completed.
- OAuth 2.0 Standards for secure authentication.
Verified by leading platforms

Google Certified Integration Partner
Officially certified by Google for API integrity and secure integrations with Google Workspace and Gmail.

Shopify Certified Integration Partner
Officially certified by Shopify for secure e-commerce integrations and order management.
Official Subprocessors

Hetzner Online
Infrastructure
Enterprise cloud hosting in Germany. Tier III+ data centers, dedicated servers, full EU data residency.

Mollie
Payments
Secure payment processing in the EU. PCI-DSS compliant, no storage of card details.
Cusmato Internal
Data Processing
Internal AI infrastructure and data processing. Own servers, no external AI APIs for customer data.