Cybervize - Cybersecurity-Lösungen

Trust Center

Security and operations of the Cybervize platform, in one place. This page collects what is publicly substantiated today. We discuss detailed documentation in a first conversation.

Hosting and data residency

  • Hosting and data processing exclusively in data centers in Germany, with OVHcloud. OVHcloud is a European provider and is not subject to the US CLOUD Act.
  • OVHcloud is the platform's only hosting subprocessor.
  • Product development and security engineering in Germany.

Tenant isolation and access

  • Strict tenant isolation between clients, including multi-tenant consulting operation.
  • Role model with RBAC in four layers; four-eyes rules for critical actions.
  • Audit-proof log of every action; automatically expiring access keys.

AI governance

  • Three operating modes for AI processing: Sovereign Mode (self-operated language model in Germany, no data passed to external model providers), BYOK (customer-owned API keys) and Managed Mode with defined data residency.
  • The Cybervize Navigator answers only from data covered by read permissions, cites source and metric, and logs every question audit-proof.
  • AI agents are in testing with selected customers: suggesting is the default, acting requires four-eyes approval, hard locks, a kill switch, and automatic registration in the EU AI Act registry.

Operations and assurance

  • External penetration test of the platform by secuvera GmbH. Summary available on request.
  • Multiple backups per day; recovery time objective (RTO) and recovery point objective (RPO) of 24 hours each.
  • Availability and support commitments are contractually defined. We state the specifics in the proposal.
  • Full JSON data export and scheduled data deletion after contract end.
  • Our own ISMS runs on the Cybervize platform; certification to ISO 27001 is in preparation.

Reporting vulnerabilities

  • Responsible disclosure process with encrypted reporting and a safe harbor commitment.

Go to the responsible disclosure page

Privacy and contracts

  • Privacy policy in accordance with GDPR.
  • A standard data processing agreement under Art. 28 GDPR is available.
  • We discuss technical and organizational measures in a first conversation.

Go to the privacy policy

Questions about the security architecture?

We are happy to walk you through the platform, the operating model and the documentation.

Book a first conversation