Cybervize

Trust Center

Security and operations of OdySecure, the security platform by Cybervize, in one place. This page collects what is publicly substantiated today. We discuss detailed documentation in a first conversation.

Hosting and data residency

  • Hosting and data processing exclusively in data centers in Germany, with OVHcloud. OVHcloud is a European provider without a US parent company and, under current law, is not subject to the US CLOUD Act.
  • OVHcloud is the platform's only hosting subprocessor.
  • Product development and security engineering in Germany.

Tenant isolation and access

  • Strict tenant isolation between clients, including multi-tenant consulting operation.
  • Role model with RBAC in four layers; four-eyes rules for critical actions.
  • Audit-proof log of every action; automatically expiring access keys.
  • What sits behind the log: it is designed as an append-only log at the database level. Triggers reject every UPDATE and every DELETE on log entries, regardless of which application writes. In the administration interface the log is read-only, including for accounts with the highest application privileges. This layer holds against any writing application, but not against interventions made with database administration rights. How we separate those rights is something we set out in the initial call.

AI governance

  • Three operating modes for AI processing: Sovereign Mode (self-operated language model in Germany, no data passed to external model providers), BYOK (customer-owned API keys) and Managed Mode with defined data residency.
  • The OdySecure Navigator answers only from data covered by read permissions, cites source and metric, and logs every question audit-proof.
  • AI agents are in testing with selected customers: suggesting is the default, acting requires four-eyes approval, hard locks, a kill switch, and automatic entry in the platform's own AI system inventory.

Operations and assurance

  • External penetration test of the platform by secuvera GmbH. Summary available on request.
  • Multiple backups per day; recovery time objective (RTO) and recovery point objective (RPO) of 24 hours each. The recovery time is evidenced by a restore test; the recovery point follows from the backup interval, which sits well below it. We go through the test record in the initial call.
  • Availability and support commitments are contractually defined. We state the specifics in the proposal.
  • Full JSON data export and scheduled data deletion after contract end.
  • Our own ISMS runs on OdySecure; certification to ISO 27001 is in preparation.

Reporting vulnerabilities

  • Responsible disclosure process with encrypted reporting and a safe harbor commitment.

Go to the responsible disclosure page

Privacy and contracts

  • Privacy policy in accordance with GDPR.
  • A standard data processing agreement under Art. 28 GDPR is available.
  • We discuss technical and organizational measures in a first conversation.

Go to the privacy policy

Questions about the security architecture?

We are happy to walk you through the platform, the operating model and the documentation.

Book a first conversation