Security & privacy

Security a helpdesk actually needs.

A support tool sees your customers' most sensitive data – IBANs, credentials, contract details. inbrix is built from the ground up to keep that data protected and keep it inside the EU.

Security & privacy

Customer data is not training material.

A helpdesk sees IBANs, license keys, shop credentials. inbrix treats that the way it must be treated.

EU AI Act

Transparency obligation met – with nothing to configure.

Article 50 requires people to be told when an AI is talking to them. inbrix does it automatically: in the chat widget, the web form and every bot email – including a header marker and a clear path to a human.

AES-256-GCM for credentials

Authenticated encryption in the DB. Never plaintext, never in the env.

The AI runs in Europe

Your tickets are processed in the EU – by the language models too. On every plan.

ISO/IEC 27001BSI C5

Made & hosted in Germany

Our own Kubernetes cluster at Hetzner in Germany, in certified data centers. No data leaves for a third country.

Redaction before memory

IBANs, cards, tokens, names removed before any text hits AI search.

Signed links, constant-time

No timing leak. Missing key? The app refuses to boot.

Every email sandboxed

Isolated iframe with its own CSP – scripts and remote content are blocked.

Tenant isolation via Postgres RLS

The database itself enforces separation – row-level, not just in application logic. Every query runs under that policy.

Your data trains nothing

Never handed to model training – disabled at every provider. Only redacted text ever reaches the search index.

A key per tenant

Per-tenant keys: on deletion the key is destroyed – crypto-shredding, not “we deleted it”. Export any time.

Common security questions

What data protection officers ask first.

Where is the data hosted?

Exclusively in Germany, on our own Kubernetes cluster at Hetzner – in data centers certified to ISO 27001 and BSI C5 (Germany's federal cloud-security standard). AI processing stays in EU member states too – no data leaves for a third country.

Is inbrix itself ISO 27001 certified?

The data centers inbrix runs in, along with our core EU subprocessors, are already ISO 27001 certified. inbrix as a company does not yet hold its own ISO 27001 certification – we're currently preparing it and plan to complete it in Q1 2027.

Is inbrix GDPR-compliant?

Yes. Processing under Art. 28 GDPR with a DPA, documented technical and organisational measures, and a public subprocessor list with a 30-day change notice.

Is our data used for AI training?

No. Training on customer data is contractually excluded and technically disabled at every AI provider. Only redacted text ever reaches the search index.

How are tenants isolated?

Via Postgres Row Level Security – the database itself enforces separation row by row, not just the application logic. Every query runs under that policy, including the application's own.

How is data encrypted?

TLS 1.2+ in transit, AES-256 at rest, plus AES-256-GCM field encryption for credentials. Each tenant has its own key.

What happens on deletion?

The tenant-specific key is destroyed (crypto-shredding) – the data becomes unreadable, including in backups. A full export is available at any time.

Does inbrix meet the EU AI Act?

The Art. 50 transparency obligation is built in: the chat widget, web form and bot emails mark AI use automatically, including a header marker and a clear path to a human.

One more buying criterion?

Is ISO 27001 a dealbreaker for you?

Tell us with one click. It shows us how much our own certification matters to customers – and if you like, we'll reach out the moment it's in place.