Data location
Primary infrastructure runs in Germany on Hetzner Online GmbH. Object storage, Postgres, and Redis live on the same data centre footprint. EU/EEA residency is the default for content, account, and donor data.
Access
Loracta engineering staff use SSH-key access bound to a personal credential. All production reads/writes are logged. We do NOT read tenant content for any purpose other than essential support — and when support requires it, we ask first and audit the access.
What we never do
- Sell, rent, or otherwise transfer your data to third parties for marketing.
- Use your content to train AI models for our benefit or anyone else's.
- Inject tracking scripts into your tenant-rendered public pages.
- Allow tenants to read other tenants' content via the API or admin.
AI providers
Search and the workspace AI assistant use Anthropic Claude, Google Gemini, and (for transcription) Groq Whisper. Both Anthropic and Google have signed EU SCC supplementary measures. No tenant content is used for provider training.
Authentication
Email + password with optional TOTP MFA. OAuth via Google and Microsoft (Apple TBD). SSO via SAML/OIDC available on the Scale tier. Sessions sign cookies with HS256 against a per-environment SECRET_KEY.
Encryption
Data in transit is protected with TLS today. Backups and stored files are being moved to encryption at rest (SSE-S3); roll-out is in progress. Per-tenant Postgres-row encryption is on our compliance roadmap below.
Audit log
Every administrative action is recorded in a tenant-scoped audit log: who, what, when, request id, IP (truncated after 30 days), user-agent hash. Tenants can export their audit log on demand via the workspace.
Ownership
Your content remains yours. The Terms of Service grant Loracta the limited right to host, transmit, and process it for the platform service — nothing more. On termination, you export your archive and we delete your data within 30 days unless you choose extended retention.
GDPR
Loracta complies with the GDPR. See our Privacy policy, DPA, and Your rights.
Subprocessors
See the full and dated list at /subprocessors.
Incident reporting
We disclose security incidents that affect customer data via the workspace inbox within 72 hours of discovery, in line with GDPR Art. 33 obligations. Detailed post-mortems are shared with affected tenants within 14 calendar days.
Compliance roadmap
- SOC 2 Type 1 (in scope on conversion to Established tier and above).
- ISO 27001 (on the roadmap for 2027).
- Per-tenant row-level encryption keyed by tenant master key.
- SIEM forwarding (opt-in, action-whitelisted) for tenants on Scale.