Trust centre

Security, hosting and compliance

This page lists the measures with which knowmind protects your data and upholds your rights under the GDPR — not in marketing terms, but as a plain account of what is actually in place.

Hosting and data location

Servers in Nuremberg, Germany, at Hetzner Online GmbH

Data centre certified to ISO 27001 (NBG1)

No data transfer outside the EU unless you connect a US model yourself

Daily database backup, seven days retention

Encryption

In transit: TLS 1.3 with HSTS preloading

Your own AI keys: AES-256-GCM with a tenant-specific key; the plain text is never stored permanently

Access tokens: cryptographically hashed with a server-side pepper and a token-specific salt — not reconstructable even with full database access

Sign-in without a password: one-time link, valid 24 hours, redeemable once

Tenant separation

Strict separation of workspaces at database level — the tenant filter is enforced by the database, independently of the application code

A separate body of data per workspace, with every single record marked

The application database user cannot bypass this separation

Security log per workspace

Sub-processors (as of 2026-05-16)

ProviderPurposeCountryDPA
Hetzner Online GmbHServer hostingGermanyin place
Stripe Payments Europe Ltd.Payment processingIrelandSCC + GDPR
ALL-INKL.COM — Neue Medien MünnichTransactional email (own SMTP delivery)Germanyin place

Changes are announced 30 days in advance to the address held in your account. Objection and extraordinary termination are possible.

Your rights under the GDPR

Access (Art. 15): export in the dashboard, available immediately

Rectification (Art. 16): memories can be edited directly in the interface

Erasure (Art. 17): you delete individual memories yourself; full account deletion you request by email to info@schuebeler-consulting.de — we confirm the deletion within 30 days

Data portability (Art. 20): JSON export, complete, without lock-in

Right to lodge a complaint: the data protection authority of North Rhine-Westphalia (LDI NRW)

Data processing agreement

For business customers, the data processing agreement under Art. 28 GDPR is already part of the terms. A separately signed version on letterhead we send on request to info@schuebeler-consulting.de.

Read the full text (German) →

Reporting vulnerabilities

knowmind runs an open security policy under RFC 9116. If you find a vulnerability, please report it to security@schuebeler-consulting.de. We reply within 72 hours.

/.well-known/security.txt

Security review

On 16 May 2026 an internal security audit against the OWASP Top 10 took place, extended by tests of the tenant separation. Eleven findings were recorded in total:

  • Two findings rated critical — all fixed
  • Two findings rated high — all fixed
  • Four findings rated medium — all fixed
  • Three findings rated low — all fixed

An external security review by an independent provider is planned for the third quarter of 2026.