Back to home

Security

Last updated: July 2026

Infrastructure & Hosting

IONOS Cloud

HansaChat runs on IONOS Cloud infrastructure. Core application data is stored in a managed MySQL-compatible Database as a Service (DBaaS), and uploaded files are stored in IONOS Cloud Object Storage.

Encryption in Transit

HTTPS & TLS Encryption

We use HTTPS and TLS. Your data is encrypted between your browser and our servers. Your provider or any other man-in-the-middle cannot see it.

Encryption at Rest

Your Data

Account, workspace, and message data is stored in a managed MySQL-compatible Database as a Service (DBaaS) on IONOS Cloud.

All free and demo users have shared infrastructure. All paid workflows have their own database.

Your Files

Uploaded files are stored in IONOS Cloud Object Storage and encrypted at rest using server-side encryption.

IONOS Cloud Object Storage uses AES-256 for server-side encryption.

User Authentication Policy

  • Passwords are securely hashed using bcrypt with automatic salts. Even if the database is stolen, passwords cannot be directly recovered.
  • 2FA is available and highly recommended to enable.
  • User sessions are protected with encrypted cookies and expire after inactivity.
  • Session IDs are regenerated on login to prevent hijacking.

Access Control & Roles

  • Every workspace member may join any public channel and read its content.
  • Any member of a private channel may invite any user. Users cannot join private channels on their own (except during creation).
  • Workspace admins or owners cannot see the content of private channels unless they are members of it.
  • Workspace admins and owners cannot see direct messages.

Platform Level Access

HansaChat, as the platform operator, has the technical capability to access workspace data, including emails, messages, and channel memberships, strictly for maintenance, troubleshooting, or legal compliance. We respect your privacy and do not access your data without consent or necessity.

Backups & Disaster Recovery

Encrypted Restic Backups

All backups are encrypted and compressed with Restic. They are stored in the Frankfurt region, with copies in the UK (London) and Sweden (Stockholm).

Current retention strategy is:

  • Backup schedule: every 6 hours.
  • Keep all snapshots for 7 days.
  • Then keep 1 daily snapshot for 30 days.
  • Then keep 1 weekly snapshot for 12 weeks.
  • Then keep 1 monthly snapshot for 12 months.

Logging & Monitoring

HansaChat uses Sentry for logging and monitoring.

Tracking & Analytics

HansaChat is collecting only basic information such as your browser name, country and visited pages. We do not log IP addresses or any information that may identify you. All the information stored in the self-hosted service and not transfered to any third parties.

GDPR Compliance

As we host our services in Germany and operate within the European Union, we are fully committed to GDPR compliance. This includes:

  • Right to access your personal data
  • Right to rectification of inaccurate data
  • Right to erasure ("right to be forgotten")
  • Right to data portability
  • Right to object to processing

Questions About Security?

We take security seriously and are happy to answer any questions you may have about our security practices, data handling, or compliance.

Responsible Disclosure

If you discover a security vulnerability, please report it to us responsibly by emailing igor@hansa.chat. We will investigate all reports and work to address any issues promptly.