Floriti was built for privacy-sensitive registers — so security is not a feature, it is the architecture. Here is exactly how we protect your data, with no marketing fog.
Most SaaS products put all customers into one shared database and separate them with software rules. Floriti does not.
Every customer gets their own application instance and their own PostgreSQL database. Your data is physically separated from other customers — a bug or breach in one tenant cannot leak into another.
All connections use TLS (HTTPS) with automatically renewed certificates. Direct database access for reporting is TLS-encrypted as well.
The reporting database port is protected by an IP allowlist that you control yourself from your admin area — closed by default.
Granular role-based access (admins, editors, approvers, readers), user groups, and optional single sign-on via OpenID Connect with your identity provider.
Every change is logged with per-field edit history — who changed what, and when. Approval workflows add a tamper-resistant four-eyes principle.
Passwords are stored only as salted hashes. Sessions use signed tokens with per-instance secrets — every customer instance has its own keys.
Floriti runs on servers in Falkenstein, Germany, operated by Hetzner Online GmbH — in data centers certified to ISO 27001. Data stays in the EU.
Our infrastructure provider Hetzner is certified to ISO 27001 (information security management). Floriti itself is not yet ISO-certified — we say that openly. Our processes are built to be certification-ready as we grow.
Application, databases and backups are located in Germany. Transactional e-mail is sent via Brevo (EU-based provider).
Every customer database is backed up automatically every night, with 14 days of retention. Restores are performed on request as part of support.
AI features are optional, off by default, and designed so your documents stay under your control.
The AI knowledge base (semantic search / RAG) runs on a self-hosted embedding model on our own servers. Your uploaded documents are never sent to third-party AI services for indexing.
AI analysis is disabled for every new instance and only activated on your explicit request — you decide whether AI touches your data at all.
If you enable AI analysis, the text you submit is processed by Anthropic (Claude) via API. Anthropic does not use API data to train its models by default. This is documented in our data processing agreement.
The paperwork your data protection officer will ask for — ready when you are.
We provide a data processing agreement per Art. 28 GDPR including technical and organisational measures (TOM, Art. 32 GDPR) — available on request by e-mail.
We keep the list deliberately short: Hetzner (hosting, Germany), Brevo (e-mail, EU) — and Anthropic (AI, only if you enable AI analysis). No advertising or analytics processors.
Full data export (Excel/CSV/ZIP, including attachments) is built in — no lock-in. On contract end, your instance and database are deleted completely on request.
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Hosting, infrastructure | Germany (Falkenstein) |
| Brevo (Sendinblue SAS) | Transactional e-mail | EU (France) |
| Anthropic PBC | AI analysis — only if enabled by you | USA (opt-in only) |
Security pages love vague promises. We prefer verifiable facts — and we tell you what we are not (yet).