Trust Center

Everything your security and procurement team will ask for, in one place, no sales call required. AshNote is built on a simple premise: the strongest data protection is data we physically cannot read.

Architecture in one paragraph

Secrets are encrypted in your browser (AES-256-GCM via WebCrypto) before they reach us. The decryption key travels in the URL fragment, which browsers never transmit to servers. Our database stores ciphertext, an IV and a token hash, nothing else. Drops hard-delete on their final read or expiry. Full technical deep-dive: Security page.

Compliance documents

📄 Data Processing Agreement (AVV)

Art. 28 GDPR agreement incl. instructions, confidentiality, breach notification and deletion duties. German master; English version on request.

View AVV (German) →

🔒 Technical & Organizational Measures

Concrete TOMs per Art. 32 GDPR: encryption, access control, deletion concept, logging. Specific to this product, not boilerplate.

View TOMs →

📋 Records & questionnaires

Records of processing activities (Art. 30) excerpt and answers to SIG-Lite-style security questionnaires available on request: trust@ashnote.io

Subprocessors

Kept deliberately short. We notify DPA customers before adding or replacing a subprocessor.

ProviderPurposeLocationData touched
Hetzner Online GmbHApplication & database hostingGermany (Falkenstein/Nuremberg)Ciphertext, account & audit metadata
Stripe Payments Europe Ltd.Subscription billing (Team plan)EU (Ireland)Billing contact & payment data, never drop content
Brevo (Sendinblue GmbH)Transactional email (account verification, login notices)EU (Germany/France)Email address, never drop content
Netlify, Inc.Static marketing site onlyGlobal CDNNo customer or drop data

Status: July 2026. Production rollout may adjust this list; DPA customers are notified in advance.

Data residency & GDPR

  • Application and database run in German data centers (Hetzner, ISO 27001-certified facilities).
  • Drop content is client-side encrypted: we act as a processor that cannot access the processed content.
  • Personal data we do process: account e-mail, organization data, audit metadata (IPs stored as SHA-256 hashes only), billing via Stripe.
  • Hard deletion by design: burn-after-read and TTL expiry remove data permanently, purged every 60 seconds.
  • No advertising trackers; no third-party scripts on drop pages (they could read the URL fragment).

Responsible disclosure

Found a vulnerability? Report it to security@ashnote.io. We respond within 48 hours, fix verified issues promptly and credit reporters who wish to be named. The client-side cryptography is open source: auditing it is welcome, not just tolerated.

Certification roadmap

Honest status instead of badges: we are a young product. Planned in order: independent penetration test with published summary, ISO 27001 certification, and an official Art. 42 GDPR certification (AUDITOR scheme) as we grow. We publish results here as they land, and we will never buy a decorative "GDPR seal" that carries no legal weight.