Skip to content

Security & Compliance

Enterprise-grade security on ISO 27001:2022-certified infrastructure, with GDPR compliance and German data residency. Protecting it is our top priority.

ISO 27001:2022
Aligned
GDPR
Compliant
Made in Germany
EU Data Residency
AES-256-GCM
Encryption

How We Handle Your Data

Transparency is key. Here's exactly what happens to it.

We Do

  • Process your text in memory only
  • Encrypt all data in transit (TLS 1.2+)
  • Encrypt anything sensitive at rest (AES-256-GCM)
  • Maintain audit logs for compliance
  • Process it only in Germany (EU)

We Don't

  • Store your original text content (unless you opt in to Operation History)
  • Train AI models on it
  • Share it with Meta, Google, or any third-party AI provider
  • Move it outside the EU
  • Keep logs of processed content

Frequently Asked Questions

Where is my data processed?

It's processed on ISO 27001:2022 certified servers in Falkenstein, Germany (Hetzner), and never leaves the EU. No third-party sub-processors handle your text.

Is cloak.business GDPR compliant?

Yes. We support full GDPR compliance with a dedicated Data Processing Agreement (DPA), EU-only residency, and transparent handling. We act as your processor under the regulation.

Does cloak.business store my text?

No. Text submitted for analysis is processed in memory and immediately discarded. We do not log, store, or retain any text content. Only metadata (token counts, timestamps) is stored for billing.

What encryption standard is used?

Everything in transit uses TLS 1.3. Reversible encryption uses AES-256-GCM with user-held keys (zero-knowledge architecture). The Desktop App uses XChaCha20-Poly1305 for local vault encryption.

Is the infrastructure ISO 27001 certified?

Yes. Our hosting provider (Hetzner) holds ISO 27001:2022 certification. The infrastructure includes dedicated servers (not shared cloud), encrypted storage, and automated security monitoring.

Need More Details?

Explore our comprehensive security documentation or contact us for specific compliance requirements.