Security & Data Protection
Your technical documentation is among your company's most valuable data. That is why security and data protection are not an afterthought but the foundation of AI Technikakte – verifiable, without marketing promises.
Hosted in Germany
All AI Technikakte data is stored and processed on servers in Nuremberg, Germany (Hetzner Online GmbH, German data center). No data is stored outside the EU. A data processing agreement pursuant to Art. 28 GDPR is in place with our hosting provider.
Encrypted in Transit
All connections to the customer portal and website are HTTPS-only – unencrypted requests are redirected automatically. Transport is secured via TLS with modern cipher suites; certificates renew automatically.
Encrypted Backups
Backups of your data are encrypted (AES-based encryption with strong key derivation) before being stored. Without the corresponding key, a backup cannot be read.
No AI Training on Your Data
Your documents and queries are never used to train AI models – neither by us nor by our AI provider. A data processing agreement is in place with the AI provider; data sharing for training purposes is contractually and technically disabled. On request, we will offer fully self-hosted AI models on German servers in the future.
Tenant Isolation & Roles
Each customer company is strictly separated from others within the portal. A fine-grained role model (from read-only access through maintenance and shift management to company administration) ensures employees can only see and change what their role requires.
Traceability
Security-relevant events are logged. For documents, AI Technikakte additionally keeps a dedicated, long-retention document log: uploads, views, downloads, replacements, approvals and deletions remain traceable at any time – a building block for your audit readiness.
Account Security
Changes to user accounts (email address, password) require confirmation via one-time code. The affected person is automatically informed by email about every account change. Binding password requirements apply; login attempts are rate-limited.
GDPR
We operate in line with the EU General Data Protection Regulation: data processing agreements with all relevant providers, a transparent privacy policy, short retention periods for access logs (30 days), and documented technical and organisational measures.
What we are working on
To us, honesty is part of security: we are in our pilot phase and continuously raising our security level. Currently in preparation: file-system-level encryption of the live database and regular independent security assessments. We answer questions about this openly – including in detail.
Security questions or reports?
Write to support@ai-technikakte.de – we usually respond within one business day.