PricingSecurity
Security & privacy

Good service starts with trust.

From support tickets to website chats: see how inbrix protects customer data, where it is processed and which agreements apply.

Security & privacy

Customer data is not training material.

Protect credentials, keep organisations separate and make AI processing transparent.

Encrypted credentials

Credentials are stored with additional AES-256-GCM encryption.

The AI runs in Europe

Your tickets are processed in the EU – by the language models too. On every plan.

ISO/IEC 27001BSI C5

Made & hosted in Germany

Our own Kubernetes cluster at Hetzner in Germany, in certified data centers. No data leaves for a third country.

Remove sensitive details before AI search

Detected sensitive information is removed before content enters AI search.

Protected access links

Signed links protect access to shared content.

Display emails in isolation

Email content is displayed in isolation. Scripts and remote content are blocked.

Keep customer data separate

The database enforces separation between organisations in addition to application-level checks.

No training on customer data

Your content is not used to train AI models.

A key for each organisation

Each organisation has its own key. It is destroyed on deletion; you can export your data beforehand at any time.

EU AI Act

Transparency obligation met – with nothing to configure.

Article 50 requires people to be told when an AI is talking to them. inbrix does it automatically: in the chat widget, the web form and every bot email – including a header marker and a clear path to a human.

Common security questions

What data protection officers ask first.

Where is the data hosted?
Exclusively in Germany, on our own Kubernetes cluster at Hetzner – in data centers certified to ISO 27001 and BSI C5 (Germany's federal cloud-security standard). AI processing stays in EU member states too – no data leaves for a third country.
Is inbrix itself ISO 27001 certified?
The data centers inbrix runs in, along with our core EU subprocessors, are already ISO 27001 certified. inbrix as a company does not yet hold its own ISO 27001 certification – we're currently preparing it and plan to complete it in Q1 2027.
Is inbrix GDPR-compliant?
Yes. Processing under Art. 28 GDPR with a DPA, documented technical and organisational measures, and a public subprocessor list with a 30-day change notice.
Is our data used for AI training?
No. Training on customer data is contractually excluded and technically disabled at every AI provider. Only redacted text ever reaches the search index.
How are tenants isolated?
Via Postgres Row Level Security – the database itself enforces separation row by row, not just the application logic. Every query runs under that policy, including the application's own.
How is data encrypted?
TLS 1.2+ in transit, AES-256 at rest, plus AES-256-GCM field encryption for credentials. Each tenant has its own key.
What happens on deletion?
The tenant-specific key is destroyed (crypto-shredding) – the data becomes unreadable, including in backups. A full export is available at any time.
Does inbrix meet the EU AI Act?
The Art. 50 transparency obligation is built in: the chat widget, web form and bot emails mark AI use automatically, including a header marker and a clear path to a human.
One more buying criterion?

Is ISO 27001 a dealbreaker for you?

Tell us with one click. It shows us how much our own certification matters to customers – and if you like, we'll reach out the moment it's in place.