Security & trust

Compliance software has to be auditable itself.

Datargo runs Databurg the way we recommend it to customers: hardened, documented, traceable. Here's what you need to know.

Architecture

Six pillars, no marketing waffle.

What we do technically and organisationally to keep your compliance data safe.

Hosting

Cloud hosting exclusively in Frankfurt am Main. Hetzner and AWS Frankfurt. No data processing outside the EU.

Encryption

TLS 1.3 in transit, AES-256 at rest. Database backups encrypted and stored georedundantly.

Access control

Role-based permissions, SSO via SAML/OIDC, SCIM provisioning, mandatory MFA for admin accounts. Least privilege as the default.

Audit logs

Every security-relevant action (login, data access, configuration change) is logged immutably and is visible to customer admins.

Backup & recovery

Daily backups, 30-day retention, RPO < 24h, RTO < 4h. Disaster recovery is tested quarterly and documented.

Sub-processors

The full list of our data processors is kept transparently in the Trust Center. Changes are announced 30 days in advance.

Certifications

What we can prove, and what we're working on.

We state things as they are. No badges that mean nothing.

GDPR-compliant processing with a DPA under Art. 28 ISO 27001 audit scheduled for Q3 2026 SOC 2 Type II in preparation from Q1 2027 Penetration tests annually by external providers Bug bounty programme in planning (Q2 2026) TISAX conformity for automotive customers in preparation

Responsible disclosure

Security researchers and pentesters are welcome. We respond within 48 hours and publish fixes transparently.

Send findings to security@datargo.com PGP key on request Acknowledgement within 48 hours Patch timeline depends on severity (critical < 7 days) Hall of Fame for validated reports
Trust Center

Want more detail? We'll send you the security whitepaper.

Architecture diagram, pentest summary, DPA template and sub-processor list. Available under NDA.

Request the security whitepaper

A short enquiry with your company and use case. We'll send the package within 24 hours.

Request the whitepaper