Trust

What we do — and what we do not claim.

EU hosting & isolation

Cloud instances run in EU data centers. Each customer gets a dedicated instance — not a row in a shared table. Your data never shares a database with another customer's data.

Secrets never live in documents

Credentials are referenced as cred:// pointers — never stored inside label definitions, flow configurations, logs or test data. The secret store is separate from the document store by architecture, not by policy.

Outbound-only runners

Runners initiate all connections. No inbound firewall rule is needed on your network. This is an architectural property, not a configuration option.

Signed binaries

Every release is signed. Checksums are published alongside the binaries. Verify before you run.

Certificate rotation

Runner certificates are automatically rotated at two-thirds of their validity window. The rotation window is computed from the actual certificate lifetime — never from a hardcoded 90-day constant. Failed rotations trigger an alert.

Quality verification

Every label renderer change is verified against golden-file pixel diffs at 203, 300 and 600 dpi. A single changed pixel requires a documented, reviewed justification. This is not a test suite — it’s a quality gate that prevents silent visual regressions.

DPA (AVV)

A Data Processing Agreement is available for download: /legal/dpa/

Responsible disclosure

Found a security issue? Contact us at /security/. We take reports seriously and respond promptly.

What we do not claim: We make no ISO, TISAX or other certification claims. When (and if) we earn them, we will say so here. Until then: nothing.