Security & privacy

Security a helpdesk actually needs.

A support tool sees your customers' most sensitive data – IBANs, credentials, contract details. inbrix is built from the ground up to keep that data protected and never let it leave the EU.

Security & privacy

Customer data is not training material.

A helpdesk sees IBANs, license keys, shop credentials. inbrix treats that the way it must be treated.

EU AI Act

Transparency obligation met – with nothing to configure.

Article 50 requires people to be told when an AI is talking to them. inbrix does it automatically: in the chat widget, the web form and every bot email – including a header marker and a clear path to a human.

AES-256-GCM for credentials

Authenticated encryption in the DB. Never plaintext, never in the env.

EU inference guarantee

In EU-strict mode your tickets never leave the EU – not even the AI.

Made & hosted in Germany

Hetzner, our own k8s cluster. No US-cloud detour.

Redaction before memory

IBANs, cards, tokens, names removed before any text hits AI search.

Signed links, constant-time

No timing leak. Missing key? The app refuses to boot.

Every email sandboxed

Isolated iframe with its own CSP – scripts never get through.

Tenant isolation via Postgres RLS

The database itself enforces separation – row-level, not just in application logic. No query can slip past it.

Your data trains nothing

Never handed to model training – disabled at every provider. Only redacted text ever reaches the search index.

A key per tenant

Per-tenant keys: on deletion the key is destroyed – crypto-shredding, not “we deleted it”. Export any time.

Common security questions

What data protection officers ask first.

Where is the data hosted?

Exclusively in Germany, on our own Kubernetes cluster at Hetzner. No detour via a US cloud. Processing stays in the EU.

Is inbrix GDPR-compliant?

Yes. Processing under Art. 28 GDPR with a DPA, documented technical and organisational measures, and a public subprocessor list with a 30-day change notice.

Is our data used for AI training?

No. Training on customer data is contractually excluded and technically disabled at every AI provider. Only redacted text ever reaches the search index.

How are tenants isolated?

Via Postgres Row Level Security – the database itself enforces separation row by row, not just the application logic. No query can slip past it.

How is data encrypted?

TLS 1.2+ in transit, AES-256 at rest, plus AES-256-GCM field encryption for credentials. Each tenant has its own key.

What happens on deletion?

The tenant-specific key is destroyed (crypto-shredding) – the data becomes unreadable, including in backups. A full export is available at any time.

Does inbrix meet the EU AI Act?

The Art. 50 transparency obligation is built in: the chat widget, web form and bot emails mark AI use automatically, including a header marker and a clear path to a human.

Get started

Create your account.

Name, business email, done. No credit card, no contract term.

  • Every feature in your first month
  • Your data stays in Germany
  • Cancel any time, export included