Trust center

Worker regions in the EU and East Africa. Account data in EU PostgreSQL.

Compliance

  • GDPR: applicable (contract and legitimate interest).
  • NIS2: in scope. Access control, encryption, and incident handling are documented in the architecture record.
  • SOC 2: not attested. No SOC 2 report has been issued.
  • ISO 27001: not attested. No ISO 27001 certificate has been issued.

Encryption

At rest: AES-256-GCM. In transit: TLS 1.2+.

Subprocessors

  • HetznerCompute, volumes, and object storage
  • CoolifyContainer orchestration control plane