Your data, protected.

Floriti was built for privacy-sensitive registers — so security is not a feature, it is the architecture. Here is exactly how we protect your data, with no marketing fog.

🇩🇪 Hosted in Germany 🗄️ One database per customer ⚖️ GDPR / DSGVO 💾 Daily backups 📈 99.5 % uptime SLA

Isolation by architecture

Most SaaS products put all customers into one shared database and separate them with software rules. Floriti does not.

🗄️

Dedicated instance & database

Every customer gets their own application instance and their own PostgreSQL database. Your data is physically separated from other customers — a bug or breach in one tenant cannot leak into another.

🔐

Encryption in transit

All connections use TLS (HTTPS) with automatically renewed certificates. Direct database access for reporting is TLS-encrypted as well.

🧱

Customer-controlled DB firewall

The reporting database port is protected by an IP allowlist that you control yourself from your admin area — closed by default.

👤

Roles, groups & SSO

Granular role-based access (admins, editors, approvers, readers), user groups, and optional single sign-on via OpenID Connect with your identity provider.

📜

Full audit trail

Every change is logged with per-field edit history — who changed what, and when. Approval workflows add a tamper-resistant four-eyes principle.

🔑

Hardened accounts

Passwords are stored only as salted hashes. Sessions use signed tokens with per-instance secrets — every customer instance has its own keys.

Hosting in Germany

Floriti runs on servers in Falkenstein, Germany, operated by Hetzner Online GmbH — in data centers certified to ISO 27001. Data stays in the EU.

🏢

ISO 27001 certified data centers

Our infrastructure provider Hetzner is certified to ISO 27001 (information security management). Floriti itself is not yet ISO-certified — we say that openly. Our processes are built to be certification-ready as we grow.

🇪🇺

EU data residency

Application, databases and backups are located in Germany. Transactional e-mail is sent via Brevo (EU-based provider).

💾

Daily backups

Every customer database is backed up automatically every night, with 14 days of retention. Restores are performed on request as part of support.

AI without data leakage

AI features are optional, can be switched off completely at any time, and are designed so your documents stay under your control.

🔒

Self-hosted knowledge base

The AI knowledge base (semantic search / RAG) runs on a self-hosted embedding model on our own servers. Your uploaded documents are never sent to third-party AI services for indexing.

🎚️

Opt-in by your admin

In paid plans, AI analysis stays deactivated until one of your admins deliberately enables it — a documented opt-in. In demo workspaces it is active for trying things out and can be switched off completely at any time. You can also bring your own API key or EU/on-premise endpoint.

🤝

Transparent AI processing

While AI analysis is enabled, the text you submit is processed by Anthropic (Claude) via API. Anthropic does not use API data to train its models by default. This is documented in our data processing agreement.

GDPR & contracts

The paperwork your data protection officer will ask for — ready when you are.

📄

Data Processing Agreement (AVV)

We provide a data processing agreement per Art. 28 GDPR including technical and organisational measures (TOM, Art. 32 GDPR) — available on request by e-mail.

🏗️

Sub-processors

We keep the list deliberately short: Hetzner (hosting, Germany), Brevo (e-mail, EU) — and Anthropic (AI, only while AI analysis is enabled). No advertising or analytics processors.

🗑️

Deletion & export

Full data export (Excel/CSV/ZIP, including attachments) is built in — no lock-in. On contract end, your instance and database are deleted completely on request.

Sub-processorPurposeLocation
Hetzner Online GmbHHosting, infrastructureGermany (Falkenstein)
Brevo (Sendinblue SAS)Transactional e-mailEU (France)
Anthropic PBCAI analysis — only if enabled by youUSA (opt-in only)
📘 Want the bigger picture? Our GDPR guide shows which duties a register tool covers — and how to tackle the rest, with a 90-day plan: The complete GDPR roadmap →

Contracts & SLA

Clear commitments instead of vague promises — our contract documents in one place.

📈

99.5 % availability (SLA)

Our Service Level Agreement guarantees 99.5 % monthly availability for paid plans — measured automatically, with service credits if we miss it. Maintenance windows are announced at least 48 hours in advance.

🛟

Support 7 days a week

Support requests are handled every day of the week — including weekends. Critical incidents (instance unreachable) receive a qualified response within 4 hours during service hours.

📋

Terms of Service (B2B)

Clear B2B terms with a 30-day money-back guarantee on paid plans, a fair-use policy for AI features and storage, and a guaranteed data export period at the end of the contract.

📦

Service description per plan

Plans, limits and included quotas are documented transparently in a service description — the same numbers you see on the pricing page.

All contract documents — Terms of Service, SLA, service description, data processing agreement (AVV) and TOM — are available on request before you sign anything: info@floriti-register.com

Honesty over badges

Security pages love vague promises. We prefer verifiable facts — and we tell you what we are not (yet).

Floriti is a young product. We are not ISO 27001 certified yet, and we do not claim "military-grade" anything. What we do promise: an architecture built on isolation, hosting that never leaves Germany, daily backups, and straight answers to security questionnaires — usually within a few business days. External penetration testing is part of our security roadmap.
Security contact: Found a vulnerability or need our AVV/TOM documents? Write to us — security reports are handled with priority. info@floriti-register.com →