Your data, protected by design.

Hosted in the EU, isolated per tenant, encrypted in transit, with role-based access and an audit trail on every change.

GDPR-compliant EU hosting RFC-3161 timestamp Working-time compliant
How we protect your data

Security on every layer

Hosted in the EU

Application and data run on Scaleway infrastructure entirely within the EU, behind Cloudflare for TLS, WAF and DDoS protection.

Tenant isolation

Every tenant has its own database. Cross-tenant access is structurally impossible — not just a filter.

Encrypted in transit

All traffic runs over HTTPS only, with HSTS and a strict set of security headers; secrets are stored encrypted and rotatable.

Role-based access

Granular roles per module and record. The MCP server inherits the same permissions over OAuth.

Audit trail

Every sensitive change is logged — who, what, when, with old and new values. Exportable for review and compliance.

2FA & SSO

Two-factor authentication for all accounts, single sign-on and SCIM on the enterprise plan.

Architecture

One database per tenant — no shared storage.

vemix is multi-tenant over separate PostgreSQL databases. Authentication runs over JWT with 2FA and SSO, billing through Paddle, operated on Scaleway infrastructure in the EU behind Cloudflare.

Cloudflare · TLS, WAF, DDoS protection
Scaleway · EU
PostgreSQL · DB per tenant
JWT · 2FA · SSO · SCIM
Signatures & GDPR

E-signature with timestamp, GDPR by design.

The signature module produces simple electronic signatures (SES) with an RFC-3161 timestamp and an audit certificate appended to the final PDF. Data export, deletion and minimisation are part of the product, not an afterthought.

RFC-3161 timestamp on the sealed PDF Data export & deletion built in Working-time tracking compliant by design

Questions about data protection or processing agreements?

We provide a data processing agreement, technical and organisational measures and a sub-processor list on request.