Skip to content

Security and privacy at Discoverify

Customer interviews contain voices, names and confidential statements. This page shows where we process them, what we have actually put in place to protect them, and what is still missing. We only claim what we can back up.

Hosting

Hetzner, Germany

AI processing

Amazon Bedrock, EU

Transcription

AssemblyAI, EU

Certifications

none yet

Data location

Hosted in Germany

Application, database, media files and backups are hosted by Hetzner in Germany.

Transcription in the EU

Speech recognition and speaker separation are handled by AssemblyAI through its EU endpoint (AWS region Dublin). After transcription, we request deletion of the audio at AssemblyAI. Voice recognition still runs only on our own server.

AI in the EU

Claude and the embedding model run on Amazon Bedrock with EU inference profiles (source region eu-west-1, Ireland). Requests stay within EU regions.

Security measures

In place and checked in our security review. What’s still missing is listed under “Compliance status”.

Application

  • Tenant isolation in the database

    Every table holding customer data is restricted to its own workspace via Postgres row-level security. The application uses a database role without superuser or bypass privileges.

  • Passwordless login with rate limiting

    No passwords. Sign in with a magic link or a Microsoft or Google account (OpenID Connect). Login links are valid for 15 minutes and can be used only once. At most 5 requests per email address in 15 minutes, including unknown addresses. Login emails are sent via Resend from the EU region (Ireland) using the sender domain mail.getdiscoverify.com.

  • Secure sessions

    The session cookie is httpOnly, Secure and SameSite=Lax. Cross-origin write requests are rejected.

  • Access tokens stored as hashes only

    Personal access tokens for MCP are stored only as SHA-256 hashes, scoped to the workspace, read-only and revocable at any time.

  • Quotes only from the database

    Quotes in answers come verbatim from the stored transcript, not from the language model. If there is no evidence, the answer is “not found”.

  • Audit log

    Security-relevant events such as deletions and every MCP call are logged with IDs and counters, without conversation content or search terms.

Infrastructure

  • Encrypted transport

    TLS 1.2 and 1.3 with automatically renewed certificates; HTTP redirects to HTTPS and HSTS is enabled. Plus a Content Security Policy that prevents embedding in third-party sites.

  • Hardened containers

    All services run in containers without Linux capabilities (with a few documented exceptions), with a read-only file system and no privilege escalation (no-new-privileges).

  • Minimal attack surface

    Only ports 80, 443 and 22 are reachable from outside. Database, API and workers have no public ports. The host firewall blocks everything else.

  • Key-only SSH

    No password login, no direct root login, a single deploy user. fail2ban blocks repeated failed attempts, and security updates are installed automatically.

Your control

  • Deletion on request

    Interviews can be deleted along with all derived data: transcript, statements, media and references in saved answers. The same goes for voice profiles and people.

  • Full export

    Download a ZIP with all interviews, metadata as JSON and the media files at any time. Your data belongs to you.

  • Roles

    Admins manage the workspace, billing and members; members work with the interviews.

AI and your data

  • No training on your data. According to AWS, Amazon Bedrock inputs and outputs are not used to train models and are not shared with model providers such as Anthropic (AWS Bedrock FAQ). We don’t train models on customer data ourselves either.
  • Only text goes to the language models. We send text excerpts from transcripts to Bedrock, never audio. Audio goes only to AssemblyAI in the EU for transcription.
  • Voice profiles are biometric data. They are computed and stored only on our own server, are not part of the export and can be deleted at any time. Once deleted, the person is no longer recognized automatically.
  • Answers with evidence. The language model phrases the points; the quotes come verbatim from the database and jump to the moment in the audio.

Subprocessors and service providers

ProviderPurposeRegionRole
Hetzner Online GmbHServers, storage and backupsGermanyProcessor
AssemblyAI Inc.Transcription and speaker separationEU (EU endpoint, AWS eu-west-1 Dublin)Processor
Resend (Plus Five Five, Inc.)Sending login and system emailsData: Email address, email content including login linkSending in the EU (eu-west-1, Ireland); metadata and logs in the USAProcessor
Amazon Web Services EMEA SARL (Amazon Bedrock)AI models for summaries, answers and semantic search (Claude, Cohere Embed)EU regions (source region eu-west-1, EU inference profile)Processor
Paddle.com Market LimitedOrdering, payment, taxes, invoices (Merchant of Record)United Kingdom (adequacy decision)Independent controller for payment data

If this list changes, we update it here. Details on processing are in our Privacy Notice.

Backups

The database is backed up daily and encrypted. Restoring from backup has been tested.

Compliance status

Today

  • Built with the GDPR in mind: data processed in Germany and the EU, deletion and export built in.
  • Data Processing Agreement (DPA) under Art. 28 GDPR: read online and save as PDF.
  • No certifications. Discoverify has no SOC 2, no ISO 27001 and no comparable external audit.

Planned

  • plannedContent Security Policy with nonces instead of “unsafe-inline”
  • plannedRestrict SSH access to fixed admin IP addresses as well
  • plannedIndependent audit (e.g. SOC 2) once our customer base and revenue support it

Report a vulnerability

Found a vulnerability? Please email us before you publish it. We’ll confirm receipt and keep you posted on the fix.

security@getdiscoverify.com

Machine-readable at /.well-known/security.txt. Please don’t run tests that disrupt the service or access other people’s data.