Skip to main content

Trust Center

Security & data protection

Kontorion processes billing, tax and accounting data – exactly the information a finance team doesn't hand over lightly. This page summarises how we handle it. It describes only what is true today; legally binding details are set out in our Privacy Policy.

  • GDPR-native
  • GoBD-compliant
  • Hosted in the EU
  • DPA under Art. 28
  • TLS 1.3 · HSTS
  • Row-level security

Data location & EU hosting

Your data is processed in European data centres and never leaves the EU. Kontorion runs as a managed cloud – deliberately EU-only. All processing locations for the website hosting are within the EU/EEA; no transfer to third countries takes place as part of the hosting. The infrastructure providers we use are disclosed in the hosting section of the Privacy Policy.

Protection against unauthorised access

Kontorion is secured in layers – so that a single mistake doesn't immediately expose data. All traffic runs encrypted over TLS; unencrypted connections are rejected and blocked via HSTS. Access is tied to a sign-in through our identity provider (Keycloak / OIDC), and every access token is verified cryptographically. API keys are never stored in clear text, only as a hash; webhooks are HMAC-signed; requests are rate-limited.

The most important line of defence sits in the database itself. Each tenant is separated from every other at the row level via row-level security, and the application runs under a database role that cannot bypass that separation in normal operation. The tenant boundary is therefore not drawn in application code alone but enforced by PostgreSQL – an additional layer that holds even if a mistake is made above it.

Operations are built for a small attack surface, too. Credentials and keys are not kept in source code or in Git but in a separate secret manager, from which they are loaded only at runtime. The database is not publicly reachable; the application containers run without root privileges and with restricted kernel access. The platform runs on managed Kubernetes in the EU, kept continuously patched. We take automatic, encrypted backups of all data with point-in-time recovery over 30 days, complemented by a high-availability replica with automatic failover.

GDPR-native & data processing

At Kontorion, GDPR compliance is not an add-on but a foundation of the architecture. The hosting and infrastructure providers we use act as processors within the meaning of Art. 28 GDPR, and data processing agreements are in place with each of them. Which providers these are is listed in our public subprocessor register. We provide a data processing agreement (DPA) for the business use of Kontorion on request – just write to contact@frontieralgorithmics.com. Which personal data is processed for which purposes and on which legal basis is fully documented in the Privacy Policy.

GoBD-compliant archiving & audit log

Records stay traceable and audit-proof. Kontorion provides a GoBD-compliant audit trail with archiving. Tax rules are shipped versioned and are fully traceable in the audit log. The accounting is designed to be replay-safe: plans, prices and products are versioned, every subscription pins to an immutable plan_version, and catalog edits never silently mutate live invoices. For each invoice, the FX rate and tax rule are frozen at finalize – existing records remain untouched.

EU-only infrastructure & self-hosted analytics

On kontorion.eu we use no tracking cookies and no advertising pixels. No third-party scripts for advertising, social media or cross-site tracking are loaded. For audience measurement, we use the open-source web analytics tool Umami, which we run exclusively on our own infrastructure under analytics.kontorion.eu – cookie-free and with no transfer to third parties. Contact and demo requests also run through self-hosted software (Formbricks) on our own infrastructure. For details, see the web analytics and cookies sections of the Privacy Policy.

Company & accountability

The operator and controller within the meaning of the GDPR is:

Frontier Algorithmics UG (haftungsbeschränkt)
Koppoldstr. 1
86551 Aichach, Germany

Full mandatory information is available in our Legal Notice; the competent supervisory authority and your rights as a data subject are listed in the Privacy Policy.

To be honest about where we are: Kontorion is in Early Access with a small group of design partners. This page states only what is actually true today – no invented certifications and no promises we cannot yet keep.

Contact for security matters

Have a security or data-protection question, want to request a DPA, or need to report a potential issue? Write to contact@frontieralgorithmics.com. General enquiries also reach us via the contact form.

Last updated: July 2026

Book a demo

Book a technical demo. 15 minutes with an engineer on your specific pricing model and tax setup. No hard sell.

Prefer email? Reach us at contact@frontieralgorithmics.com