Security & Trust

Inscryble is in early stage. Here you'll find everything we actually have today — no promises we can't keep.

Architectural commitments

Zero Raw Data

Only SHA-256 hashes and metadata reach our servers. Never raw customer text.

2FA on all accounts

Mandatory two-factor authentication (TOTP — Google Authenticator, Authy, 1Password).

Audit log

Every admin action logged with Before/After diff, exportable as CSV.

Hosting and data location

Sub-processors

Inscryble uses only the trusted vendors listed below. Any change to sub-processors is communicated to customers with 30 days notice.

Vendor Purpose Location DPA
IONOS SE Hosting and data storage Germany (EU) DPA
Stripe Payments Europe Ltd Payment processing Ireland (EU) DPA

Data Processing Agreement (DPA)

Every customer receives a DPA as part of the contract. Download the template below.

Security contact