Security & privacy

Your employees' data — protected, private, under your control

Employee communication means sensitive data. We take it seriously at every level: from EU hosting and GDPR compliance, through encryption, two-factor authentication and round-the-clock monitoring, to private AI that takes no data outside.

EU hosting RODO TLS 1.3 + AES-256 2FA SSO SIEM monitoring Penetration testing Backups Private AI
Where your data lives

In the European Union — and under your control

EU hosting

Servers and data kept in data centres within the European Union, in line with GDPR requirements.

Data processing agreement

With every client we sign a data processing agreement that clearly defines the scope and responsibilities of each party.

Private AI

The AI assistant can run on your infrastructure — data and documents do not go to OpenAI or any other external company.

Own server and code option

The option to deploy on your infrastructure and a source-code licence — full control and no vendor lock-in (a clear exit scenario).

Certified data centres

Infrastructure hosted in ISO 27001-certified data centres (OVHcloud) — the certification covers the provider's infrastructure.

Encryption & transmission

Protected in transit and at rest

Encrypted transmission (TLS 1.3)

All communication between app and server is encrypted with the latest HTTPS / TLS 1.3 standard.

Encryption of data at rest

Data stored on servers is encrypted with AES-256.

Security headers

Enforced HTTPS (HSTS) and a set of protective headers: Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy.

Authentication & access control

Access only for the right people

Two-factor authentication (2FA)

An extra layer of verification at login, protecting accounts from unauthorised access.

Corporate login (SSO)

Login via a corporate account using OIDC / OAuth, with automatic locking of inactive sessions.

Secure session tokens

Access tokens stored server-side and revoked instantly, complemented by cryptographic request signing (integrity).

Roles & permissions

Role-based access to content — administrator, super-administrator, management per country and site.

Firewalls

A firewall protecting the infrastructure; administrative access limited strictly to authorised people.

Infrastructure security

Protection built into daily operations

Monitoring & incident detection

Continuous infrastructure monitoring and security incident detection in a SIEM-class system.

AI oversight & nightly updates

An AI agent monitors servers around the clock and detects intrusion attempts, and runs automatic updates every night — with a daily security report.

Penetration testing

Regular penetration tests carried out by independent specialists.

Backups every 12 hours

Automatic backups performed every 12 hours, with monitoring of their completion.

Updates & vulnerabilities

Regular system updates and ongoing vulnerability management.

99.9% availability

Services maintained at 99.9% availability, with continuous monitoring of operation.

Disaster recovery

Service restored within 12 hours of an outage; RPO and RTO of 12 hours.

Mobile app & employee privacy

Designed around data minimisation

No access to private data

The app does not reach into private data on the employee's phone — it operates within its own company content.

Login without an email address

A production worker can use the app without a company email — logging in via QR code or in kiosk mode.

Optional contact details

Phone number and private email are not required — we collect only the data necessary for the app to work.

Do-not-disturb mode

The employee can mute notifications outside working hours — peace during private time.

Content moderation

The ability to report and moderate offensive content posted in the app.

Team & processes

Security is also about people

Security training

Regular team training on security and data protection principles.

Workstation protection

Antivirus protection on the team's workstations.

Compliance & employee rights

GDPR from day one

Security & compliance documentation

Full documentation — available on request

We maintain formal security documentation and rely on recognised industry standards. Because of its confidential nature we share it after verification — leave your contact details and we'll get in touch and provide the selected documents.

Information Security Policy

Data protection rules, responsibilities, IT safeguards and incident handling. Available on request.

IT System Management Instruction

Rules for securely managing the IT system that processes personal data. Available on request.

Risk assessment (Art. 32 GDPR)

An assessment of risks to data processed in the app, carried out under Art. 32 GDPR. Available on request.

GDPR information clauses

Fulfilment of information obligations towards the people whose data we process. Available on request.

Confidentiality statement

The team's commitment to keep entrusted data confidential. Available on request.

Penetration test report

Results of independent security tests of the infrastructure and application. Available on request.

Which documents are you interested in?

Questions about the security of your data?

During a demo we'll show the technical details, architecture and data handling using your company as an example.

Let's talk