Trust Center
Security and operations of the Cybervize platform, in one place. This page collects what is publicly substantiated today. We discuss detailed documentation in a first conversation.
Hosting and data residency
- Hosting and data processing exclusively in data centers in Germany, with OVHcloud. OVHcloud is a European provider and is not subject to the US CLOUD Act.
- OVHcloud is the platform's only hosting subprocessor.
- Product development and security engineering in Germany.
Tenant isolation and access
- Strict tenant isolation between clients, including multi-tenant consulting operation.
- Role model with RBAC in four layers; four-eyes rules for critical actions.
- Audit-proof log of every action; automatically expiring access keys.
AI governance
- Three operating modes for AI processing: Sovereign Mode (self-operated language model in Germany, no data passed to external model providers), BYOK (customer-owned API keys) and Managed Mode with defined data residency.
- The Cybervize Navigator answers only from data covered by read permissions, cites source and metric, and logs every question audit-proof.
- AI agents are in testing with selected customers: suggesting is the default, acting requires four-eyes approval, hard locks, a kill switch, and automatic registration in the EU AI Act registry.
Operations and assurance
- External penetration test of the platform by secuvera GmbH. Summary available on request.
- Multiple backups per day; recovery time objective (RTO) and recovery point objective (RPO) of 24 hours each.
- Availability and support commitments are contractually defined. We state the specifics in the proposal.
- Full JSON data export and scheduled data deletion after contract end.
- Our own ISMS runs on the Cybervize platform; certification to ISO 27001 is in preparation.
Reporting vulnerabilities
- Responsible disclosure process with encrypted reporting and a safe harbor commitment.
Privacy and contracts
- Privacy policy in accordance with GDPR.
- A standard data processing agreement under Art. 28 GDPR is available.
- We discuss technical and organizational measures in a first conversation.
Questions about the security architecture?
We are happy to walk you through the platform, the operating model and the documentation.
Book a first conversation