Skip to content

Security and data protection

Answers for IT, data protection and procurement

This page answers the questions IT security, data protection officers and procurement ask first.

Operations and hosting

Application and language models are hosted with IONOS in Germany, the models in the Berlin data centre. The stack is fully open-source based and uses no proprietary cloud services. Running on your own infrastructure is possible: ValueSpoc ships as an operations package with Kubernetes and Helm, a software bill of materials, a vulnerability gate in the delivery pipeline and a German operations manual.

Tenant isolation and access

Tenant isolation is anchored technically, enforced at database level and additionally checked server-side per request, with automated tests. Every write is checked against organisation and role, the interface is not the security boundary. User management connects to OIDC systems such as Keycloak via the standard, while roles and organisation membership continue to be assigned in ValueSpoc. Two-factor sign-in via authenticator app is available per account.

AI with guardrails

The agent uses only defined, permission-checked tools on your own organisation's data. Personal data is pseudonymised before transmission to the language model, answers carry source references, AI content is labelled. Effective actions require a human confirmation. Training on customer data is contractually excluded. You choose the model yourself, and each installation can connect its own OpenAI-compatible endpoint.

Data protection in the product

The privacy module keeps records of processing activities and data subject requests, with configurable deletion routines and retention periods per organisation. Data categories can be released or blocked for AI use. A register of AI deployments shows, per deployment, the associated processing activity and the state of the data protection impact assessment. The register grades no risk and replaces no legal review.

Protocol and evidence

Governance decisions and security-relevant events are logged append-only, and each entry is chained via the hash of its predecessor. A retroactive change would be technically provable. The protocol serves the traceability of decisions, not the monitoring of employees.

Architecture at a glance

Hosting in Germany (application and language models)
Yes
On-premise operation runnable
Yes
Strict tenant isolation anchored technically
Yes
OIDC integration (e.g. Keycloak) possible via the standard
Yes
Two-factor sign-in activatable per account
Yes
Register of AI deployments with DPIA status
Yes
All functions via REST interfaces per OpenAPI
Yes
Fully runnable on standard Kubernetes (application layer, database provided by the operator)
Yes
Training AI models on customer data
No
Proprietary cloud services as part of the solution
No
Certification of the application itself
Planned for 2026/27

Documents and scrutiny

Standardised data protection documents

Data processing agreement, technical and organisational measures per Art. 32 GDPR and a security concept are available. A data protection impact assessment is prepared together with you for the concrete use case.

Data subject rights

Configurable deletion routines, deletion by authorised staff or on request. Data categories can be released or blocked for AI use, retention periods are configurable per organisation.

Certifications of the infrastructure

The hosting infrastructure at IONOS is certified and audited to ISO 27001. That certification covers the operation of the data centre, not the ValueSpoc application. Every release additionally passes a vulnerability gate with a software bill of materials.

Our own certifications

Certifications for ValueSpoc are being planned. Those that are mandatory in our target markets are scheduled for 2026/27. Until then, what is verifiable today applies: the data processing agreement, technical and organisational measures under Art. 32 GDPR, the security concept, the software bill of materials and a vulnerability gate on every release. If your procurement requires a particular certification, tell us early. We will tell you whether we will hold it by the time of your process.

Independent of the supplier

What you need to keep running ValueSpoc without us at any time.

Your data is yours

All content can be exported in full through the REST interfaces at any time, without our involvement.

Running it yourself

ValueSpoc ships as an operations package with Kubernetes and Helm, with a software bill of materials and an operations handbook. Moving it into your own infrastructure is possible at any time.

Source code escrow

We will set up source code escrow with a trustee on request.

An open stack

The stack is entirely open-source based and uses no proprietary cloud services. There is no component only we could operate.

Documents for your review

We provide the data processing agreement, the catalogue of measures and the security concept up front on request, and answer questions from IT and data protection directly.

Cookies on this website

We only store what this website needs to work. Optional analytics stays off until you allow it. You can change your choice at any time. Cookie Policy · Privacy Policy