Security & trust

Security and privacy, built in — not bolted on

Aequo is designed GDPR-first from the database schema up: every tenant gets its own isolated database, every sensitive action is hash-chained into a tamper-evident audit log, and every compliance workflow required in Germany ships in every edition — never as a paywalled add-on.

Data residency & isolation

EU-hosted infrastructure with one dedicated database per tenant (stancl/tenancy). No shared tables, no cross-tenant query paths — isolation is structural, not a permission check.

Encryption & secure delivery

TLS in transit, encryption at rest, and every document or export served through signed, permission-checked URLs — files are never publicly addressable.

Access control

RBAC on every edition, ABAC policy conditions on Enterprise, TOTP 2FA, and SSO via SAML/OIDC and Microsoft Entra ID. Field-level permissions restrict sensitive attributes per role.

Tamper-evident audit log

Every sensitive action is written to a hash-chained activity log — any retroactive edit breaks the chain and is detectable. Retention up to 10 years on Enterprise, with SIEM export.

GDPR tooling by default

DSAR export, deletion and anonymization workflows, versioned consent records, and Betriebsrat-aware reporting — compliance features are never gated behind an add-on.

Vulnerability management

Continuous internal security review of every module before release. Formal certifications are on our roadmap — ask your account team for current status.

Certifications & attestations

We publish our certification roadmap transparently rather than implying coverage we don't have yet.

SOC 2 Type II — in progressISO 27001 — roadmap

Data Processing Agreement

A standard Art. 28 GDPR DPA is included with every SaaS subscription; Enterprise contracts can negotiate addenda directly.

Request our DPA

Sub-processors

A current, versioned list of every sub-processor we use — infrastructure, email delivery, AI inference — with the data categories each one touches.

View sub-processor list

Found a security issue?

We run a responsible disclosure program. Report findings to security@aequo.example — we acknowledge within 2 business days.