Trust Center

Self-disclosure with data — instead of a purchased seal.

We ask our customers for evidence, not claims. So we start with ourselves. Legal status checked on 01/09/2026.

Server location

Hosting

Falkenstein, DE

Platform and database entirely in Germany — no US cloud.

Backups

Hosting

Double, daily

Server snapshots plus database backups, retained for 14 days (Art. 32 GDPR).

Encryption

Hosting

TLS, everywhere

Every connection is transport-encrypted; certificates renew automatically.

Attack surface

Hosting

Minimal

Firewall reduced to what's necessary, security updates applied automatically.

Registration

Access

Invitation only

No open sign-up — every account is intentional and attributable.

Login

Access

MFA (TOTP)

Two-factor for platform accounts — and for our own operator access.

Permissions

Access

Role-based

Employees see and confirm, owners control.

AI access to your data

AI

None

All generators run deterministically on our own servers — your data trains nothing.

Development

AI

AI-assisted, without customer data

We build with Anthropic Claude — customer data never flows into it.

Labelling

AI

Art. 50 AI Act

We label AI-generated marketing content — the same duty our product walks you through.

Working principle

Compliance

Law first

Legal statements are built from the statute text and carry a source citation with its version.

Our own mistakes

Compliance

Corrected publicly

Every review lands in the change log — most recently Sections 30/38 BSIG.

Unproven citations

Compliance

Release blocked

If we can't prove something against the primary text, we'd rather hold our release.

Self-application · EU AI Act

Completed on 11/08/2026

We passed our own product — here is the proof.

The EU AI Act walkthrough, completed by our own management with exactly the package you can buy — no special view, no polished numbers. These figures come live from the same database from which customers get their own evidence package.

AI inventory

3 systems

ChatGPT, Claude, GitHub Copilot — honestly small, we don't use more.

Usage policy

Version 1

Generated from the inventory — Art. 4 AI Act, as amended by Regulation (EU) 2026/1744.

Training rate

100%

8 certificates in this tenant — 1 of them completed personally by the management.

Labelling

Disclosure active

Decision documented under Art. 50(4) AI Act — we disclose AI content that could be mistaken for genuine.

Management's certificates

AI Competence under Art. 4 EU AI Act · CV-KI-KOMPETENZ-TEAM-2QZCWR

Our own run-through found four bugs in our product — all four are fixed. That's exactly why we do this: nobody should have to buy a tool the maker doesn't use itself.

Every framework at a glance

Self-disclosure from our own running software — the same tables from which customers get their evidence package. Not a certificate: ISO certificates are only issued by an accredited body.

Your security foundation (ISMS)

8 of 11 requirements met

As of 13/08/2026 · legal status checked on 01/09/2026

AI Act (EU AI Act)

9 of 9 requirements met

As of 11/08/2026 · legal status checked on 01/09/2026

NIS2 Germany (BSIG)

4 of 8 requirements met

As of 11/08/2026 · legal status checked on 01/09/2026

Data protection (GDPR)

3 of 11 requirements met

As of 13/08/2026 · legal status checked on 01/09/2026

ISO 27001 — information security certificate

20 of 25 requirements met

As of 11/08/2026 · legal status checked on 01/09/2026

ISO 9001 — quality management (voluntary)

voluntary standard

24 of 31 requirements met

As of 11/08/2026 · legal status checked on 01/09/2026

ISO 14001 — environmental management (voluntary)

voluntary standard

23 of 26 requirements met

As of 11/08/2026 · legal status checked on 01/09/2026

Subprocessors

Complete list — no hidden chains

ProviderPurposeLocation
Hetzner Online GmbHHosting the platform and databaseFalkenstein, Germany
united-domains AGDomains, DNS and the outbound email mailboxStarnberg, Germany

Payment processing: Payments run through the EU entity of our payment service provider — Stripe Payments Europe, Ltd. in Dublin, Ireland. Stripe is deliberately not in the table above: it never touches your platform data, only the payment data of the person making the purchase. For that, Stripe is our processor (Art. 28 GDPR) for the payment itself and a controller in its own right for what it must do as a payment institution — fraud prevention, anti-money-laundering and due diligence. You enter payment details directly with Stripe; they do not pass through our servers. Details in the privacy policy, section “Payment processing”.

For your customers

You get a Trust Center just like this one.

What you see here is the result of our own platform — and you build the same thing with Compliverse: complete the Walkthrough or your modules, and your evidence becomes a linkable Trust Center profile for large customers, tenders and vendor questionnaires. Up to date straight from your dashboard, nothing to gather by hand.

See packages →

Security contact

Found a vulnerability?

Write to kontakt@compliverse.de — we take reports seriously, respond, and never penalise anyone who discloses responsibly.

Deadlines and legal bases: Legal Landscape page. No legal advice.