Trust Center
Everything your security and procurement team will ask for, in one place, no sales call required. AshNote is built on a simple premise: the strongest data protection is data we physically cannot read.
Architecture in one paragraph
Secrets are encrypted in your browser (AES-256-GCM via WebCrypto) before they reach us. The decryption key travels in the URL fragment, which browsers never transmit to servers. Our database stores ciphertext, an IV and a token hash, nothing else. Drops hard-delete on their final read or expiry. Full technical deep-dive: Security page.
Compliance documents
📄 Data Processing Agreement (AVV)
Art. 28 GDPR agreement incl. instructions, confidentiality, breach notification and deletion duties. German master; English version on request.
🔒 Technical & Organizational Measures
Concrete TOMs per Art. 32 GDPR: encryption, access control, deletion concept, logging. Specific to this product, not boilerplate.
📋 Records & questionnaires
Records of processing activities (Art. 30) excerpt and answers to SIG-Lite-style security questionnaires available on request: trust@ashnote.io
Subprocessors
Kept deliberately short. We notify DPA customers before adding or replacing a subprocessor.
| Provider | Purpose | Location | Data touched |
|---|---|---|---|
| Hetzner Online GmbH | Application & database hosting | Germany (Falkenstein/Nuremberg) | Ciphertext, account & audit metadata |
| Stripe Payments Europe Ltd. | Subscription billing (Team plan) | EU (Ireland) | Billing contact & payment data, never drop content |
| Brevo (Sendinblue GmbH) | Transactional email (account verification, login notices) | EU (Germany/France) | Email address, never drop content |
| Netlify, Inc. | Static marketing site only | Global CDN | No customer or drop data |
Status: July 2026. Production rollout may adjust this list; DPA customers are notified in advance.
Data residency & GDPR
- Application and database run in German data centers (Hetzner, ISO 27001-certified facilities).
- Drop content is client-side encrypted: we act as a processor that cannot access the processed content.
- Personal data we do process: account e-mail, organization data, audit metadata (IPs stored as SHA-256 hashes only), billing via Stripe.
- Hard deletion by design: burn-after-read and TTL expiry remove data permanently, purged every 60 seconds.
- No advertising trackers; no third-party scripts on drop pages (they could read the URL fragment).
Responsible disclosure
Found a vulnerability? Report it to security@ashnote.io. We respond within 48 hours, fix verified issues promptly and credit reporters who wish to be named. The client-side cryptography is open source: auditing it is welcome, not just tolerated.
Certification roadmap
Honest status instead of badges: we are a young product. Planned in order: independent penetration test with published summary, ISO 27001 certification, and an official Art. 42 GDPR certification (AUDITOR scheme) as we grow. We publish results here as they land, and we will never buy a decorative "GDPR seal" that carries no legal weight.