Your data: isolated, in the EU, always yours.
One Postgres schema per customer, encryption in transit and at rest, daily backups with per-customer restore, audit logging and a data processing agreement you can read in ten minutes. No AI trained on your data.
Structural isolation, not procedural.
- One schema per customer
Your records live in physical tables in a schema that's yours alone. Shared metadata has row-level security per tenant. Automated tests run every operation as two customers and prove neither sees the other.
- Encryption
TLS 1.3 in transit, encrypted disks at rest, email credentials and BYOK keys encrypted per tenant. Secrets kept out of the code.
- Backups and restore
Daily backups, 30-day retention, per-customer restore without affecting anyone else. Configuration snapshots before any bulk operation.
You're the controller. We're the processor. It's in writing.
The data processing agreement (DPA) is part of the terms and applies to every plan, including Free.
- Subprocessor list
Public, dated, with advance notice of changes. Hosting and transactional email in the EU; AI providers under zero-retention contracts.
- Data subject rights
Export, rectification and erasure per record, logged in the audit trail. Search by email or tax ID across every object.
- Retention and deletion
Retention rules per object; permanent deletion of the workspace on request within 30 days, with a certificate.
- Data residency
EU by default. On Enterprise, choice of region and a dedicated cluster.
The AI sees what you see. And forgets.
- No training on your data
Model providers used under zero-retention contracts. We never use customer data to train or fine-tune models.
- Same permissions as yours
Pimzi AI and MCP agents act on behalf of a user and only see what that user sees.
- BYOK
From Premium up, use your own key and your own contract with the provider. The key is encrypted per tenant.
- Full trail
Every AI action in the history, with the command, the actor and the inverse. Can be turned off per tenant or per role.
Enterprise-grade access control, at an SME price.
- Authentication
Strong passwords, app-based 2FA, passkeys. SSO/SAML and SCIM on Enterprise.
- Roles and scopes
Per object, per record (mine, team, all) and per field. Applied to the UI, API, AI and MCP.
- Audit log
Access, exports and changes. Retention from 7 days to 3 years depending on the plan; exportable.
- Certifications
Annual third-party penetration tests; report available under NDA.
Found a vulnerability? Write to us through the contact page. Responsible disclosure, response within 72 hours.