Trust centre
Security, hosting and compliance
This page lists the measures with which knowmind protects your data and upholds your rights under the GDPR — not in marketing terms, but as a plain account of what is actually in place.
Hosting and data location
Servers in Nuremberg, Germany, at Hetzner Online GmbH
Data centre certified to ISO 27001 (NBG1)
No data transfer outside the EU unless you connect a US model yourself
Daily database backup, seven days retention
Encryption
In transit: TLS 1.3 with HSTS preloading
Your own AI keys: AES-256-GCM with a tenant-specific key; the plain text is never stored permanently
Access tokens: cryptographically hashed with a server-side pepper and a token-specific salt — not reconstructable even with full database access
Sign-in without a password: one-time link, valid 24 hours, redeemable once
Tenant separation
Strict separation of workspaces at database level — the tenant filter is enforced by the database, independently of the application code
A separate body of data per workspace, with every single record marked
The application database user cannot bypass this separation
Security log per workspace
Sub-processors (as of 2026-05-16)
| Provider | Purpose | Country | DPA |
|---|---|---|---|
| Hetzner Online GmbH | Server hosting | Germany | in place |
| Stripe Payments Europe Ltd. | Payment processing | Ireland | SCC + GDPR |
| ALL-INKL.COM — Neue Medien Münnich | Transactional email (own SMTP delivery) | Germany | in place |
Changes are announced 30 days in advance to the address held in your account. Objection and extraordinary termination are possible.
Your rights under the GDPR
Access (Art. 15): export in the dashboard, available immediately
Rectification (Art. 16): memories can be edited directly in the interface
Erasure (Art. 17): you delete individual memories yourself; full account deletion you request by email to info@schuebeler-consulting.de — we confirm the deletion within 30 days
Data portability (Art. 20): JSON export, complete, without lock-in
Right to lodge a complaint: the data protection authority of North Rhine-Westphalia (LDI NRW)
Data processing agreement
For business customers, the data processing agreement under Art. 28 GDPR is already part of the terms. A separately signed version on letterhead we send on request to info@schuebeler-consulting.de.
Reporting vulnerabilities
knowmind runs an open security policy under RFC 9116. If you find a vulnerability, please report it to security@schuebeler-consulting.de. We reply within 72 hours.
Security review
On 16 May 2026 an internal security audit against the OWASP Top 10 took place, extended by tests of the tenant separation. Eleven findings were recorded in total:
- Two findings rated critical — all fixed
- Two findings rated high — all fixed
- Four findings rated medium — all fixed
- Three findings rated low — all fixed
An external security review by an independent provider is planned for the third quarter of 2026.