Trust Center
Self-disclosure with data — instead of a purchased seal.
We ask our customers for evidence, not claims. So we start with ourselves. Legal status checked on 01/09/2026.
Server location
HostingFalkenstein, DE
Platform and database entirely in Germany — no US cloud.
Backups
HostingDouble, daily
Server snapshots plus database backups, retained for 14 days (Art. 32 GDPR).
Encryption
HostingTLS, everywhere
Every connection is transport-encrypted; certificates renew automatically.
Attack surface
HostingMinimal
Firewall reduced to what's necessary, security updates applied automatically.
Registration
AccessInvitation only
No open sign-up — every account is intentional and attributable.
Login
AccessMFA (TOTP)
Two-factor for platform accounts — and for our own operator access.
Permissions
AccessRole-based
Employees see and confirm, owners control.
AI access to your data
AINone
All generators run deterministically on our own servers — your data trains nothing.
Development
AIAI-assisted, without customer data
We build with Anthropic Claude — customer data never flows into it.
Labelling
AIArt. 50 AI Act
We label AI-generated marketing content — the same duty our product walks you through.
Working principle
ComplianceLaw first
Legal statements are built from the statute text and carry a source citation with its version.
Our own mistakes
ComplianceCorrected publicly
Every review lands in the change log — most recently Sections 30/38 BSIG.
Unproven citations
ComplianceRelease blocked
If we can't prove something against the primary text, we'd rather hold our release.
Self-application · EU AI Act
Completed on 11/08/2026
We passed our own product — here is the proof.
The EU AI Act walkthrough, completed by our own management with exactly the package you can buy — no special view, no polished numbers. These figures come live from the same database from which customers get their own evidence package.
AI inventory
3 systems
ChatGPT, Claude, GitHub Copilot — honestly small, we don't use more.
Usage policy
Version 1
Generated from the inventory — Art. 4 AI Act, as amended by Regulation (EU) 2026/1744.
Training rate
100%
8 certificates in this tenant — 1 of them completed personally by the management.
Labelling
Disclosure active
Decision documented under Art. 50(4) AI Act — we disclose AI content that could be mistaken for genuine.
Management's certificates
AI Competence under Art. 4 EU AI Act · CV-KI-KOMPETENZ-TEAM-2QZCWR
Our own run-through found four bugs in our product — all four are fixed. That's exactly why we do this: nobody should have to buy a tool the maker doesn't use itself.
Every framework at a glance
Self-disclosure from our own running software — the same tables from which customers get their evidence package. Not a certificate: ISO certificates are only issued by an accredited body.
Your security foundation (ISMS)
8 of 11 requirements met
As of 13/08/2026 · legal status checked on 01/09/2026
AI Act (EU AI Act)
9 of 9 requirements met
As of 11/08/2026 · legal status checked on 01/09/2026
NIS2 Germany (BSIG)
4 of 8 requirements met
As of 11/08/2026 · legal status checked on 01/09/2026
Data protection (GDPR)
3 of 11 requirements met
As of 13/08/2026 · legal status checked on 01/09/2026
ISO 27001 — information security certificate
20 of 25 requirements met
As of 11/08/2026 · legal status checked on 01/09/2026
ISO 9001 — quality management (voluntary)
voluntary standard24 of 31 requirements met
As of 11/08/2026 · legal status checked on 01/09/2026
ISO 14001 — environmental management (voluntary)
voluntary standard23 of 26 requirements met
As of 11/08/2026 · legal status checked on 01/09/2026
Subprocessors
Complete list — no hidden chains
| Provider | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Hosting the platform and database | Falkenstein, Germany |
| united-domains AG | Domains, DNS and the outbound email mailbox | Starnberg, Germany |
Payment processing: Payments run through the EU entity of our payment service provider — Stripe Payments Europe, Ltd. in Dublin, Ireland. Stripe is deliberately not in the table above: it never touches your platform data, only the payment data of the person making the purchase. For that, Stripe is our processor (Art. 28 GDPR) for the payment itself and a controller in its own right for what it must do as a payment institution — fraud prevention, anti-money-laundering and due diligence. You enter payment details directly with Stripe; they do not pass through our servers. Details in the privacy policy, section “Payment processing”.
For your customers
You get a Trust Center just like this one.
What you see here is the result of our own platform — and you build the same thing with Compliverse: complete the Walkthrough or your modules, and your evidence becomes a linkable Trust Center profile for large customers, tenders and vendor questionnaires. Up to date straight from your dashboard, nothing to gather by hand.
See packages →Security contact
Found a vulnerability?
Write to kontakt@compliverse.de — we take reports seriously, respond, and never penalise anyone who discloses responsibly.
Deadlines and legal bases: Legal Landscape page. No legal advice.