Skip to content

Security

Your knowledge belongs to you. And only to those who should see it.

Built for companies from the database up: one permission model for everything, checked on the server, denied when in doubt. Hosted exclusively in Germany.

Principles

Four rules that apply everywhere.

Checked on the server, every time

Every action checks permissions where it happens: in the editor, in search, for the AI, via MCP or when publishing a site. When in doubt, it is denied.

What you may not see does not exist for you

Pages from other organizations or restricted pages answer with “not found” instead of “forbidden”. Not even a link reveals that they exist.

Organizations separated in the database

Every record carries its organization, and every direct foreign key includes it. PostgreSQL itself rejects references across organizations.

AI without permission shortcuts

Assistant, @AI and MCP act on behalf of the person, with exactly their permissions. The AI of a site only sees that site’s published docs. Page content reaches the model explicitly as data, not as instructions.

Control

What admins control.

Single sign-on (OIDC)

Your identity provider via OIDC, e.g. Entra ID, Okta or Keycloak. Enforced SSO for verified domains; the organization owner keeps a break-glass login.

Passkeys and two-factor

Sign in without a password or with a second factor; review and end sessions.

Audit log

Who changed permissions, structure or settings and when, including via AI, MCP and import. Protected against later changes, exportable as CSV.

Clean offboarding

Whoever is removed or suspended loses all access immediately, tokens and sessions included.

Tokens that reveal nothing

Access tokens are stored only as a hash, shown once and revocable at any time.

Public only when you choose

Public links are not indexed. Sites only show published releases, and restricted pages never go public; if a page is restricted later, it disappears at once.

Technical details

For your security review.

How it is built, not just what is promised.

Tenant isolation
Organization in every key, composite foreign keys (organization_id, id), organization check centrally before every policy.
Other organizations’ resources
HTTP 404 instead of 403, for restricted pages too: no existence oracle.
Sign-in
OIDC with PKCE, enforced SSO for verified domains, roles from IdP groups, provisioning on first sign-in, maximum session length. Plus passkeys (WebAuthn) and TOTP.
Sessions
Overview per device; “end other sessions” invalidates all others immediately.
Access tokens
Stored only as HMAC-SHA-256, shown once, read-only or read-write, revocable.
Audit log
Written in the same transaction as the change; a database trigger prevents updates and deletes. Only the retention period (two years) removes old entries. Text changes are in the version history.
AI and MCP
Run as an agent on behalf of the person through the same policies; page content is passed as data.
Sites
Own address, separate from the app, without app session or cookies; app routes do not exist there. Strict CSP (only the site’s own scripts, frame-ancestors 'none'), HTML built from a fixed list of allowed elements. The build re-checks the publishing person’s permissions; restricted, archived and deleted pages are left out and re-checked on every request, in older releases too. Custom domains only with TXT proof, re-checked daily. Custom CSS cannot load anything from other servers; the MCP server of a site is read-only.
Site AI
Answers only from the live release of the site and only from pages that are still public; no tools, no memory. Every answer is checked before the visitor sees it: no valid source, no answer; links, images and HTML from the model never get through. Proof of work instead of a CAPTCHA, no third party; limits per visitor and per site and day; its own monthly allowance, separate from the team’s AI budget. Questions are kept for 60 days, without IP addresses, with personal data masked, also before they reach the model. No cookies.
Transport and browser
TLS, HSTS, Content Security Policy with nonce, uploaded files served in a sandbox.
Hosting
Data centers exclusively in Germany, backups included. Or on your own servers.

Contracts and your data

Every plan comes with a data processing agreement under Art. 28 GDPR. AI features run through the provider you choose, your own model is possible, too. You can export all pages with their files as Markdown or HTML at any time.

Read the privacy policy

Subprocessors

ProviderPurposeLocation
Hetzner Online GmbHHosting of the platform, files and backupsGermany
Scaleway, Sweego as fallbackSending emailsFrance
Mollie B.V.Payment processingNetherlands
Your AI providerAI requests, only if you configure oneyour choice

Your knowledge. In one place you control.

Try everything in Business for 30 days, no credit card. You import Notion exports and Markdown yourselves, and you can leave any time as Markdown or HTML.

No credit card · Cancel any month · Data in Germany