SmartDataTwin
Security · Compliance

EU-compliant by default. Not as an add-on.

SmartDataTwin is built for GDPR duty as a mid-market platform — not bolted on. Hosted in Frankfurt, DPAs at onboarding, zero-retention with LLM vendors, seven-year audit log.

Six pillars

What we build on.

  • 01

    Data sovereignty

    All data in the EU (Frankfurt). Supabase Postgres + Hetzner Cloud + Hetzner Object Storage as backup.

  • 02

    Multi-tenancy

    One database, tenant isolation via `org_id` and Postgres Row-Level Security. Defense in depth.

  • 03

    LLM processing

    Anthropic with zero-retention option. OpenAI Enterprise with EU region. Mistral natively EU.

  • 04

    Encryption

    TLS 1.3 in transit. AES-256 at rest. Sensitive fields per-tenant-keyed in `pgcrypto`.

  • 05

    Audit trail

    Every action emits an event with actor, time, before/after. 7-year retention.

  • 06

    Right of access

    GDPR export via /api/dsgvo/export, deletion via /api/dsgvo/delete. Pure Postgres.

Roles

Roles & permissions.

  • Four roles out of the box

    `org_admin`, `manager`, `employee`, `external`. Per entity × action fine-grained.

  • Inheritance over site hierarchy

    Permissions automatically apply to sub-sites. Cuts maintenance dramatically.

  • Sensitive fields protected

    Pay, sick leave, HR files require an extra permission bit. Audit mandatory.

Voice

Voice data — handled deliberately.

For voice and phone modules: explicit consent before any recording. Storage exclusively EU. Retention configurable — default 90 days.

Certification

Certification roadmap.

  1. Phase 2

    External penetration test. First pilot customers live.

  2. Phase 3

    TISAX (if workshop customers). GDPR audit.

  3. Phase 4

    SOC 2 Type 1 prep (from ~10 customers).

  4. Phase 5

    ISO 27001 (from ~25 customers, > €1M ARR).

SLO

Service level.

< 300 ms
API latency p95
≥ 99.5 %
availability Phase 2
≥ 99.9 %
availability Phase 4
< 5 min
AI recommendation → UI
7 d
point-in-time recovery
30 d
backup retention
Request the security pack