Security and privacy at Discoverify
Customer interviews contain voices, names and confidential statements. This page shows where we process them, what we have actually put in place to protect them, and what is still missing. We only claim what we can back up.
Hosting
Hetzner, Germany
AI processing
Amazon Bedrock, EU
Transcription
AssemblyAI, EU
Certifications
none yet
Data location
Hosted in Germany
Application, database, media files and backups are hosted by Hetzner in Germany.
Transcription in the EU
Speech recognition and speaker separation are handled by AssemblyAI through its EU endpoint (AWS region Dublin). After transcription, we request deletion of the audio at AssemblyAI. Voice recognition still runs only on our own server.
AI in the EU
Claude and the embedding model run on Amazon Bedrock with EU inference profiles (source region eu-west-1, Ireland). Requests stay within EU regions.
Security measures
In place and checked in our security review. What’s still missing is listed under “Compliance status”.
Application
Tenant isolation in the database
Every table holding customer data is restricted to its own workspace via Postgres row-level security. The application uses a database role without superuser or bypass privileges.
Passwordless login with rate limiting
No passwords. Sign in with a magic link or a Microsoft or Google account (OpenID Connect). Login links are valid for 15 minutes and can be used only once. At most 5 requests per email address in 15 minutes, including unknown addresses. Login emails are sent via Resend from the EU region (Ireland) using the sender domain mail.getdiscoverify.com.
Secure sessions
The session cookie is httpOnly, Secure and SameSite=Lax. Cross-origin write requests are rejected.
Access tokens stored as hashes only
Personal access tokens for MCP are stored only as SHA-256 hashes, scoped to the workspace, read-only and revocable at any time.
Quotes only from the database
Quotes in answers come verbatim from the stored transcript, not from the language model. If there is no evidence, the answer is “not found”.
Audit log
Security-relevant events such as deletions and every MCP call are logged with IDs and counters, without conversation content or search terms.
Infrastructure
Encrypted transport
TLS 1.2 and 1.3 with automatically renewed certificates; HTTP redirects to HTTPS and HSTS is enabled. Plus a Content Security Policy that prevents embedding in third-party sites.
Hardened containers
All services run in containers without Linux capabilities (with a few documented exceptions), with a read-only file system and no privilege escalation (no-new-privileges).
Minimal attack surface
Only ports 80, 443 and 22 are reachable from outside. Database, API and workers have no public ports. The host firewall blocks everything else.
Key-only SSH
No password login, no direct root login, a single deploy user. fail2ban blocks repeated failed attempts, and security updates are installed automatically.
Your control
Deletion on request
Interviews can be deleted along with all derived data: transcript, statements, media and references in saved answers. The same goes for voice profiles and people.
Full export
Download a ZIP with all interviews, metadata as JSON and the media files at any time. Your data belongs to you.
Roles
Admins manage the workspace, billing and members; members work with the interviews.
AI and your data
- No training on your data. According to AWS, Amazon Bedrock inputs and outputs are not used to train models and are not shared with model providers such as Anthropic (AWS Bedrock FAQ). We don’t train models on customer data ourselves either.
- Only text goes to the language models. We send text excerpts from transcripts to Bedrock, never audio. Audio goes only to AssemblyAI in the EU for transcription.
- Voice profiles are biometric data. They are computed and stored only on our own server, are not part of the export and can be deleted at any time. Once deleted, the person is no longer recognized automatically.
- Answers with evidence. The language model phrases the points; the quotes come verbatim from the database and jump to the moment in the audio.
Subprocessors and service providers
| Provider | Purpose | Region | Role |
|---|---|---|---|
| Hetzner Online GmbH | Servers, storage and backups | Germany | Processor |
| AssemblyAI Inc. | Transcription and speaker separation | EU (EU endpoint, AWS eu-west-1 Dublin) | Processor |
| Resend (Plus Five Five, Inc.) | Sending login and system emailsData: Email address, email content including login link | Sending in the EU (eu-west-1, Ireland); metadata and logs in the USA | Processor |
| Amazon Web Services EMEA SARL (Amazon Bedrock) | AI models for summaries, answers and semantic search (Claude, Cohere Embed) | EU regions (source region eu-west-1, EU inference profile) | Processor |
| Paddle.com Market Limited | Ordering, payment, taxes, invoices (Merchant of Record) | United Kingdom (adequacy decision) | Independent controller for payment data |
If this list changes, we update it here. Details on processing are in our Privacy Notice.
Backups
The database is backed up daily and encrypted. Restoring from backup has been tested.
Compliance status
Today
- Built with the GDPR in mind: data processed in Germany and the EU, deletion and export built in.
- Data Processing Agreement (DPA) under Art. 28 GDPR: read online and save as PDF.
- No certifications. Discoverify has no SOC 2, no ISO 27001 and no comparable external audit.
Planned
- plannedContent Security Policy with nonces instead of “unsafe-inline”
- plannedRestrict SSH access to fixed admin IP addresses as well
- plannedIndependent audit (e.g. SOC 2) once our customer base and revenue support it
Report a vulnerability
Found a vulnerability? Please email us before you publish it. We’ll confirm receipt and keep you posted on the fix.
security@getdiscoverify.comMachine-readable at /.well-known/security.txt. Please don’t run tests that disrupt the service or access other people’s data.