Most recent: Risk register completed, Annex A controls scoped 2026-04-15.
Day 1. Here’s why that’s good news for you: you can read this number on day-one pre-launch. We commit to publishing it daily forever, including the unflattering ones.
VOL. 01 — TRUST CENTER
Day 1. Here’s why that’s good news for you. We commit to publishing these numbers daily forever, including the unflattering ones.
COMPLIANCE PROGRESS
Most recent: Risk register completed, Annex A controls scoped 2026-04-15.
Day 1. Here’s why that’s good news for you: you can read this number on day-one pre-launch. We commit to publishing it daily forever, including the unflattering ones.
Most recent: Trust services categories selected, auditor RFP open.
Day 1. Here’s why that’s good news for you: you can read this number on day-one pre-launch. We commit to publishing it daily forever, including the unflattering ones.
SUB-PROCESSORS
| Vendor | Role | Country | DPA |
|---|---|---|---|
| Hetzner Online GmbH | Primary application + database hosting | Germany 🇩🇪 | DPA → |
| Bunny.net (BunnyWay d.o.o.) | Static asset CDN + media streaming | Slovenia 🇸🇮 | DPA → |
| Mollie B.V. | Payment processing (SEPA, iDEAL, Bancontact, card) | Netherlands 🇳🇱 | DPA → |
| Plausible Insights OÜ | No-cookie, EU-hosted website analytics | Germany 🇩🇪 | DPA → |
| MailerSend (MailerLite EU) | Transactional email delivery | Lithuania 🇱🇹 | DPA → |
| Tutanota / Tuta GmbH | Internal team communication | Germany 🇩🇪 | DPA → |
DATA PROCESSING AGREEMENT
Our standard DPA is downloadable as a PDF. No email gate, no sales-call prerequisite. Procurement teams hate gated legal docs. So do we.
Download the DPA →AUDIT LOG
Every admin action — user removal, channel deletion, permission change,
integration install, data export — writes to an immutable
audit_events table. The Postgres role used by the application
cannot UPDATE or DELETE rows in that table. Audit-log rows can be read by
workspace admins with audit permission and exported as JSON via the in-product
Settings → Workspace → Audit log → Export flow.
The architecture guarantees integrity at the storage layer, not at the ORM layer. A bug in the application cannot tamper with the audit log.
RIGHT TO ERASURE
When a user exercises right-to-erasure, the message rows remain in place
with the body replaced by null and a tombstone marker set.
The original row identity, timestamps, and audit history are preserved
so workspace admins can see that a deletion happened — without
seeing what was deleted. We chose this over hard-deletion because hard
deletion violates the integrity property of the message log (see I3 in
our principles). Compliance-driven hard deletes are a separate, audited,
slow-path operation.
SECURITY QUESTIONNAIRE
Procurement teams have standard questionnaires (CAIQ, SIG-Lite, custom Excel grids). Send us yours, we fill it out, you get the filled PDF back by email within 72 hours. No sales call.
— BEGIN —
Free for teams up to 10. No credit card. No call required.
Create your workspace →