Security & trust
Written for the person who has to answer the security questionnaire.
Every claim on this page points at something concrete — a component, a standard, or an architectural fact you can verify in the running product. No vague reassurance.
Where your data lives
Sovereign Workspace Collaboration and Sovereign Workspace Server both run the same way: as a self-contained stack on a server you choose. You have two options, with identical architecture and a different operator:
- Self-hosted — you run it on your own hardware or a cloud provider you already trust. We hold no copies, have no access, and receive no telemetry.
- Managed by us — we operate it for you in the region you choose. We act as your data processor under a standard DPA; you remain the data controller. Pick an EU region and there is no US transfer.
A self-hosted install makes you both the data controller and the data processor. There is no cross-border transfer to document and no Standard Contractual Clauses to negotiate. Schrems II is not relevant when the data never leaves your infrastructure.
Who can read your content
Most platforms answer this with a policy. We answer it with cryptography, and we are precise about where that guarantee starts and stops.
The founding principle is that administrators administer the platform, not the data. Access to content requires the conjunction of an authenticated identity, an authorisation policy, workspace membership, a resource permission, and — in the protected tiers — an encryption key the operator does not hold.
- Standard Spaces — access is governed by permissions. Appropriate for everyday internal content. An operator with database access could read it.
- Restricted and Sealed Spaces — content is encrypted with keys the server operator never holds. For Sealed Spaces the key never leaves the browser, so an administrator with root on the machine cannot read the content, and neither can we when we host it for you.
Files are encrypted at rest in object storage, and search respects permissions — a user never sees a result they are not entitled to open.
Identity & authentication
Keycloak is the single identity provider for the whole stack. An admin creates a user once. That user then signs in and reaches their spaces, files and documents without a second password or a connection step. When someone leaves, you disable one account and they lose access everywhere.
- OIDC and SAML for federating your existing identity provider, including Active Directory.
- WebAuthn / FIDO2 — passkeys and hardware security keys (YubiKey, SoloKey, Titan).
- PKCS#11 smart-card capability for government-issued eIDs.
- Argon2id password hashing.
- Short-lived JWT access tokens with refresh rotation.
Source code you can audit
Paying customers receive the source for the software they run. Your own engineers — or an external auditor you appoint — can read exactly what is executing on your infrastructure, rather than taking a vendor's word for it. The licence covers inspection and audit, not redistribution.
Independent of any licence terms, three things are guaranteed by the architecture: the product runs on infrastructure you control, it sends no telemetry to us, and it depends on no US cloud service to operate.
Audit
Every authentication event, admin action, and policy change is logged with timestamp, actor, action, and target. Content carries its own history — page versions, file versions, and immutable baselines you can point an auditor at. Logs export to CSV and to syslog / SIEM.
Backup & recovery
You back up what you host. Everything sits in a standard
PostgreSQL database and standard object storage, so ordinary
tooling works without modification — pg_dump, restic,
borgbackup, rsync, or whatever you already run. There is no opaque
vendor backup format, and no export fee to leave.
Certification — on the roadmap, not claimed
Formal certifications — BSI C5 (Germany), SecNumCloud (France), Common Criteria, EN 301 549 accessibility — are on the roadmap. We will list them here when they are issued, and not before. See the roadmap →
Frequently asked
- Where does my data live?
- On the server you choose. Self-host on your own hardware or a European cloud (Hetzner, OVH, IONOS, Infomaniak), or have us run it as a managed deployment in the region you pick. There is no vendor cloud silently holding copies, and a self-hosted install means the data is yours, physically.
- Can your staff read our content?
- Not in Restricted or Sealed Spaces. Those use per-space encryption keys that are never held by the server operator, so an administrator with root access to the machine still cannot read the content. In standard Spaces, access is governed by authorisation rather than cryptography — an operator with database access could read content there, which is why sensitive material belongs in a Restricted or Sealed Space. We would rather state that distinction plainly than claim a guarantee we do not deliver everywhere.
- Is the source code available to inspect?
- Yes, to paying customers. You receive the source for the software you run, so your own engineers or a third-party auditor can review exactly what is executing on your infrastructure. It is licensed for inspection and audit, not redistribution.
- Do you send telemetry back to your servers?
- No. A running deployment does not phone home: nothing collects usage statistics, crash reports, or analytics. There is no licence server to call, so your workspace keeps working whether or not it can reach us.
- How is authentication handled?
- Keycloak is the single identity provider. Supported: OIDC, SAML, WebAuthn/FIDO2 (passkeys, hardware keys), and PKCS#11 smart cards. Passwords are hashed with Argon2id. Session tokens are signed JWTs with short expiry and refresh rotation. Disable one account and the user loses access everywhere.
- What about GDPR?
- GDPR-aligned by architecture. If you self-host, you are both the data controller and the data processor, so there is no third-country transfer to document and no Standard Contractual Clauses to negotiate. Under a managed deployment you choose the region, and we act as your processor under a standard DPA.
- Is the product certified (BSI C5, SecNumCloud, Common Criteria)?
- Not today. Formal certification is on the roadmap and we will list certificates here when they are issued, not before. The current position is: EU-hosted or self-hosted, GDPR-aligned, source-inspectable, and audited end to end.
- What happens if we stop paying, or you go away?
- Your deployment keeps running. There is no licence server to deactivate it and no phone-home to switch off, so the software on your infrastructure continues to work. Your data is already in your own database and object storage, in standard formats you can back up and export with ordinary tooling. Paying customers also hold the source for what they run. See the Impressum for the project's current legal status.
Send us your security questionnaire.
We will fill it in properly, including the questions where the honest answer is "not yet." Email the PDF or a link and you'll get it back completed.