ISO/IEC 27001:2022 - our host Hetzner's certification
International information security management standard. Scope: Hetzner data center infrastructure, operations and support (Nuremberg, Falkenstein, Helsinki).
Verify: Hetzner trust center
Architecture
100% self-hosted, zero third-party AI. All our models run on our European servers - no document or text is ever sent to OpenAI, Google, Anthropic or any external provider. This page documents data processing, encryption, subprocessors and our compliance commitments.
All our recognition and processing models run on our European servers. No document, no text - original or pseudonymized - is ever sent to a third-party AI provider. Nothing leaves the EU.
Your document is processed exclusively on our European servers (Hetzner, Germany), by our own self-hosted AI models. Detection and pseudonymization run on our servers: your document passes through them, encrypted in transit (TLS), and is processed in memory only for the duration of the operation. No third-party AI API (OpenAI, Google, Anthropic…) ever receives your content, and no content is ever used to train anything. For the strictest requirements, a stateless mode is available: no disk writes, no session, no retained mapping.
Every operation follows an ephemeral flow: processing, pseudonymisation, AI usage under your control, local restoration, then purge. No document content is retained in the database or application logs.
Safe-Doc runs on infrastructure hosted in the European Union, operated by Hetzner (Germany). As a European operator, Hetzner is not subject to the US CLOUD Act.
The marketing site (safe-doc.ai) and pseudonymization backend (app.safe-doc.ai) run on this infrastructure. Session data is ephemeral: processed then automatically purged.
The certifications below belong to our hosting provider. They attest to the security of the infrastructure Safe-Doc runs on - they are not Safe-Doc's own certifications (see "Our approach" below).
International information security management standard. Scope: Hetzner data center infrastructure, operations and support (Nuremberg, Falkenstein, Helsinki).
Verify: Hetzner trust center
Cloud security framework from the German Federal Office for Information Security (BSI), audited over an operating period.
Verify: Hetzner documentation
Architecture designed according to ISO 27001 principles (minimization, segregation, logging without content). ISO 27001 certification: planned when we onboard our first enterprise accounts / on-premise deployments.
The mapping (correspondence table for restoration) has a 2-hour TTL and is automatically purged. It is kept server-side for the session only, never beyond the TTL; in stateless mode, it is never persisted (returned to the client, nothing server-side). After expiry, the session becomes unrecoverable.
We log operations only: timestamp, operation type, duration, entity count by type, detected language, user identifier. No document content, no extracted personal data, no text is logged - neither in application logs nor in monitoring (aggregated metrics). Caching of user content is refused by design.
| Subprocessor | Role | Region |
|---|---|---|
| Hetzner Online GmbH | Hosting (dedicated servers, data processing) | Germany 🇪🇺 |
| Scaleway (TEM) | Transactional email only | France 🇪🇺 |
| Zoho Mail (zoho.eu) | Team mailboxes (inbound) | EU 🇪🇺 |
| Namecheap | DNS registrar (no client data) | US (DNS only) |
| Stripe | Payment / billing only (never your documents) | Stripe Technology Europe Ltd (Ireland 🇮🇪); US group - transfers under EU-US Data Privacy Framework |
Stripe only processes billing and payment data - never your documents. No document content leaves the EU.
No external AI provider on the data path: all our models are self-hosted on our European servers.
Robustness tested continuously. Internal adversarial corpus of several hundred cases (entity detection, bypass attempts, trap formats), expanded with each new scenario identified. Automated regression benches replayed weekly to guard against regression on every engine evolution.