Trust & data protection
Trust Centre
Where your data lives
Every service we rely on, plotted by where it physically processes your data. Almost all run inside the EU. The one exception, OpenAI, is bound by EU Standard Contractual Clauses, processes prompts with zero data retention, and receives only the limited context needed for AI responses.
Database, auth & realtime
Hosting & infrastructure (Germany)
Content delivery network
Payment processing & billing
Product analytics
Knowledge base, changelog & feedback
Transactional & product email
AI assistant processing
All sub-processors are bound by Data Processing Agreements. The current list is published at vaizy.com/subprocessors and mirrored in our DPA.
How your data is protected
Concrete measures, not slogans. Each one is enforced today and documented in our Privacy Policy.
The AI never sees sensitive data
AI requests pass through a server-side gateway that minimises and masks sensitive context before model processing. Client code never calls the AI provider directly.
Encrypted, always
TLS 1.2+ on everything in transit. Stored data is encrypted at rest by Supabase.
You see only your own data
Row Level Security is enforced on every database table, and role-based access controls govern what each member can do.
Sign in with a second factor
Authentication runs on Supabase Auth with multi-factor (TOTP) support, so a password alone is not enough.
Secrets stay on the server
API keys and provider credentials live in server-managed secrets. They are never shipped to the browser.
Hardened in production
Production builds and database access paths are reviewed and hardened to reduce accidental exposure and common misconfiguration risks.
Browser-level defences
HSTS, X-Frame-Options DENY, a strict Content Security Policy, and a locked-down permissions policy ship with every page.
EU AI Act transparency
AI features are labelled wherever they appear, a person stays in charge of every decision, and the assistant is never used for decisions with legal or similarly significant effects on a person, consistent with the EU AI Act (Regulation (EU) 2024/1689).
If something goes wrong
No system is risk-free, and we will not pretend otherwise. If a breach affects your data, we notify you and the Dutch supervisory authority (Autoriteit Persoonsgegevens) without undue delay, and within 72 hours of becoming aware, as GDPR requires.
What we don't claim yet
We don't hold SOC 2 or ISO 27001 certification today. We'd rather tell you that than imply a badge we haven't earned. Our security posture is built on GDPR compliance, EU data residency, and the measures above. Formal certification is on our roadmap as we grow.
Read the fine print
Every claim on this page is backed by our legal documents. Read them in full, or ask us anything.