Trust & Security

Security

Last updated: 2 August 2026

IT budget and contract data is sensitive. This page summarizes how Contrixt protects it, technically and organizationally — from hosting and encryption to access control and subprocessors.

Hosting

Contrixt runs exclusively in data centers in Germany, operated by Hetzner Online GmbH. These data centers are ISO 27001 certified. No customer data ever leaves the EU.

Encryption

Data in transit is TLS-encrypted throughout. Stored documents (e.g. uploaded invoices and contracts) and secrets (e.g. API keys, SMTP credentials) are encrypted at rest with AES-256-GCM.

Optionally, you can supply your own encryption key (bring your own key, BYOK) — in that case, your tenant's data is encrypted with this key instead of the platform key.

Tenant isolation

Contrixt is a multi-tenant application. Tenant separation is enforced not only at the application level but additionally at the database level via row-level security (RLS) — every query is scoped to the respective tenant independently of the application logic.

Backups

The database receives a full backup every day and is additionally recorded continuously via point-in-time recovery — restoration is possible for any point in time within the last 30 days.

Access & authentication

Signing in to Contrixt supports:

Subprocessors

We work with carefully selected subprocessors:

Data Processing Agreement (DPA)

A fully completed data processing agreement under Art. 28 GDPR — pre-filled with provider details, subprocessors, and the technical and organizational measures described here — can be downloaded at any time directly within the application: Administration → Settings → Data Processing Agreement (DPA).

Questions about Contrixt's security? Write to us at contact@contrixt.com. Details on how we process data are in our Privacy Policy.