Your data, protected.

Floriti was built for privacy-sensitive registers — so security is not a feature, it is the architecture. Here is exactly how we protect your data, with no marketing fog.

🇩🇪 Hosted in Germany 🗄️ One database per customer ⚖️ GDPR / DSGVO 💾 Daily backups

Isolation by architecture

Most SaaS products put all customers into one shared database and separate them with software rules. Floriti does not.

🗄️

Dedicated instance & database

Every customer gets their own application instance and their own PostgreSQL database. Your data is physically separated from other customers — a bug or breach in one tenant cannot leak into another.

🔐

Encryption in transit

All connections use TLS (HTTPS) with automatically renewed certificates. Direct database access for reporting is TLS-encrypted as well.

🧱

Customer-controlled DB firewall

The reporting database port is protected by an IP allowlist that you control yourself from your admin area — closed by default.

👤

Roles, groups & SSO

Granular role-based access (admins, editors, approvers, readers), user groups, and optional single sign-on via OpenID Connect with your identity provider.

📜

Full audit trail

Every change is logged with per-field edit history — who changed what, and when. Approval workflows add a tamper-resistant four-eyes principle.

🔑

Hardened accounts

Passwords are stored only as salted hashes. Sessions use signed tokens with per-instance secrets — every customer instance has its own keys.

Hosting in Germany

Floriti runs on servers in Falkenstein, Germany, operated by Hetzner Online GmbH — in data centers certified to ISO 27001. Data stays in the EU.

🏢

ISO 27001 certified data centers

Our infrastructure provider Hetzner is certified to ISO 27001 (information security management). Floriti itself is not yet ISO-certified — we say that openly. Our processes are built to be certification-ready as we grow.

🇪🇺

EU data residency

Application, databases and backups are located in Germany. Transactional e-mail is sent via Brevo (EU-based provider).

💾

Daily backups

Every customer database is backed up automatically every night, with 14 days of retention. Restores are performed on request as part of support.

AI without data leakage

AI features are optional, off by default, and designed so your documents stay under your control.

🔒

Self-hosted knowledge base

The AI knowledge base (semantic search / RAG) runs on a self-hosted embedding model on our own servers. Your uploaded documents are never sent to third-party AI services for indexing.

🎚️

Off by default

AI analysis is disabled for every new instance and only activated on your explicit request — you decide whether AI touches your data at all.

🤝

Transparent AI processing

If you enable AI analysis, the text you submit is processed by Anthropic (Claude) via API. Anthropic does not use API data to train its models by default. This is documented in our data processing agreement.

GDPR & contracts

The paperwork your data protection officer will ask for — ready when you are.

📄

Data Processing Agreement (AVV)

We provide a data processing agreement per Art. 28 GDPR including technical and organisational measures (TOM, Art. 32 GDPR) — available on request by e-mail.

🏗️

Sub-processors

We keep the list deliberately short: Hetzner (hosting, Germany), Brevo (e-mail, EU) — and Anthropic (AI, only if you enable AI analysis). No advertising or analytics processors.

🗑️

Deletion & export

Full data export (Excel/CSV/ZIP, including attachments) is built in — no lock-in. On contract end, your instance and database are deleted completely on request.

Sub-processorPurposeLocation
Hetzner Online GmbHHosting, infrastructureGermany (Falkenstein)
Brevo (Sendinblue SAS)Transactional e-mailEU (France)
Anthropic PBCAI analysis — only if enabled by youUSA (opt-in only)

Honesty over badges

Security pages love vague promises. We prefer verifiable facts — and we tell you what we are not (yet).

Floriti is a young product. We are not ISO 27001 certified yet, and we do not claim "military-grade" anything. What we do promise: an architecture built on isolation, hosting that never leaves Germany, daily backups, and straight answers to security questionnaires — usually within a few business days. External penetration testing is part of our security roadmap.
Security contact: Found a vulnerability or need our AVV/TOM documents? Write to us — security reports are handled with priority. info@floriti-register.com →