No ISO 27001
Enclessa holds no ISO 27001 certification and no Statement of Applicability, and there is no certification body engaged.
Trust centre
Enclessa is in open beta, and the trust centre holds the documents and answers a buyer’s legal team asks for: the controller and processor relationship, the Article 28 data processing agreement and how to get it, the subprocessor list and how changes are notified, where the service is hosted and whether data leaves the European Union, how a data subject request is handled, retention and deletion, breach notification, and the export path out. Enclessa holds no ISO 27001, SOC 2, HIPAA or comparable certification and has had no external security audit, which is stated first because it is the answer that ends some evaluations.
Open betaThe platform is being built in the open, so parts of it are not there yet, behaviour changes between releases, and no availability figure is committed while it is in beta. What is still being built.
If a certification is a procurement gate for your organisation, the answer here is no and you should stop reading. Enclessa would rather be ruled out in the first minute than in the sixth week.
Enclessa holds no ISO 27001 certification and no Statement of Applicability, and there is no certification body engaged.
There is no SOC 2 Type I or Type II report, no auditor engaged, and no observation window under way.
Enclessa holds no sector or national certification of any kind, and signs no business associate agreement.
The cryptographic library Enclessa uses has been audited independently. Enclessa’s own implementation has not been through a third-party security audit or a penetration test.
There is no report to share, because no test has been commissioned. A questionnaire asking for one gets that answer rather than a deflection.
Published detail a reviewer can check: the architecture, the data model and the whole API surface are documented, the encryption is an IETF standard through an audited open-source library, and tenant isolation is proven by a generated probe suite that fails the build if it regresses. That is evidence, and it is not a certificate.
For everything your organisation puts into the platform — messages, files, task boards, time records, personnel data — your organisation is the controller and Enclessa is the processor acting on your documented instructions. Your organisation decides why the data is there, how long it stays and who may see it; Enclessa provides the controls and carries them out.
For its own relationship with you, Enclessa is the controller: your account, billing records, support correspondence and this website. Those are governed by the privacy notice rather than by the processing agreement.
This split is why no vendor can hand you compliance as a product. Enclessa supplies the processing agreement, the security measures, the export and the deletion; the lawful basis, the retention decisions and the transparency you owe your own staff remain yours.
The Article 28 data processing agreement forms part of the terms of service and applies from the moment your organisation uses Enclessa. No separate signature is required unless your organisation requires one, in which case a signed counterpart is issued on request through the enterprise contact.
Every provider fact in the text is settled and the document is published in full. What it has not had is a review by counsel, which is stated rather than implied: the positions and the numbers below are the operator’s own and are binding, and the drafting around them has not been through an external pass.
[[ State the turnaround committed to for a signed counterpart, and whether customer paper is accepted or only the Enclessa agreement. The route itself is settled and stated above. ]]
Enclessa engages third parties for hosting, transactional email, payment processing and the delivery of push notifications. Each is bound by data protection terms no weaker than those Enclessa owes you, and Enclessa remains fully liable to you for what they do.
The authoritative list lives in the annex of the data processing agreement and is mirrored in the privacy notice. Enclessa commits to keeping those two identical, because a divergence between them is the first thing a competent reviewer checks and the fastest way to lose an evaluation.
There are 6: netcup GmbH (Karlsruhe, Germany), Mollie B.V. (Amsterdam, Netherlands), Apple Distribution International Ltd. (Cork, Ireland), Google Ireland Limited (Dublin, Ireland), OpenAI Ireland Ltd. (Dublin, Ireland), Infomaniak Network SA (Geneva, Switzerland). Each row of the annex carries the purpose and the Chapter V safeguard alongside the name. Error and uptime monitoring appears nowhere on that list because it is not outsourced — the telemetry runs on Enclessa's own infrastructure.
The authorisation is general rather than specific: you approve the practice in advance, and Enclessa gives at least 30 days’ notice in text form before engaging a new subprocessor or replacing an existing one. Within that period you may object on a substantive data protection ground, and if the objection cannot be resolved you may terminate at the point the change would take effect. That is § 6 (2) of the agreement, not a policy statement.
The hosted service runs in a single European Union region and the seller is a company established in Germany. There is no choice of country within the region on the standard plans, and Enclessa does not imply a region picker exists.
Where a named country is a requirement — which happens in parts of the public sector and in healthcare — the answer is a dedicated deployment of the same hosted service in a region you name, operated and updated by Enclessa. That is the Enterprise arrangement. It is not self-hosting, the software is never handed over, and it is quoted rather than listed.
Two things do leave the EU, and both are named in the privacy notice rather than left to be discovered. Push notifications reach Apple and Google, carrying the device token and the title and sender line — never the body of an end-to-end encrypted message — under the EU-US Data Privacy Framework or, failing that, standard contractual clauses. Email is dispatched through mail servers in Switzerland, which the European Commission has held adequate under Article 45. Nothing else does: the platform’s content, files and databases sit in datacentres in Germany, there is no error-reporting vendor, and support access is by Enclessa staff to that same infrastructure.
When one of your people exercises a right — access, rectification, erasure, restriction, portability or objection — your organisation is the controller and owes the response within the statutory deadline. Enclessa’s role is to make finding and extracting the data fast enough that the deadline is comfortable rather than tight.
The People module produces a data-subject export assembling what the platform holds about one person, and an organisation-wide export is available at any time in open formats. Enclessa assists with a request routed through the data protection contact rather than requiring it to go through general support.
One limit is architectural and cannot be engineered away: content in end-to-end encrypted conversations is stored as ciphertext for which Enclessa holds no key, so Enclessa cannot produce it in readable form for any request, from anybody. Managed channels are readable and are covered normally.
Assistance requests are answered within ten working days, and urgent ones without undue delay — § 7 (3) of the agreement. The address is privacy@enclessa.app.
Retention is configurable per organisation and the default keeps data rather than deleting it, so nothing disappears because a setting was never visited. Finer-grained retention per team and per channel is planned work and is not available today.
On termination you export everything first — that path is always open and does not require a support ticket or a negotiation — and the organisation is then deleted. Deletion is a resumable purge that derives its scope from the database schema rather than from a hand-maintained list of things to remove, which is what makes it complete rather than approximate. Object storage is cleared with it.
Statutory retention duties override deletion for the records they cover: under German commercial and tax law certain billing and accounting records must be kept for a defined period regardless of a deletion request, and those are retained for that purpose alone.
The periods are fixed rather than discretionary. Your data stays exportable for 30 days after the contract ends; Enclessa then deletes it, backups included, within a further 30 days. The one category that outlives that is invoices and accounting records, kept for eight years under § 257 (4) HGB and § 147 (3) AO as applicable from 2025 — blocked from any other processing in the meantime and deleted once the period runs out.
A personal data breach is handled to the statutory timetable rather than to a marketing one. As processor, Enclessa notifies the affected controller without undue delay after becoming aware, with what is known at the time rather than waiting for a complete picture — a first notice that says "we do not yet know the scope" is more useful than a complete one that arrives three days later.
The notification carries the nature of the breach, the categories and approximate number of records and data subjects concerned so far as known, the likely consequences, and the measures taken or proposed. Your organisation, as controller, decides whether the supervisory authority and the affected individuals must be told.
The deadline is a number, not a phrase: § 8 (1) of the agreement commits Enclessa to notifying the affected controller within 24 hours of becoming aware, and to filling in what was not known at first afterwards rather than delaying the first notice.
Breach correspondence runs through security@enclessa.app. The supervisory authority competent for Enclessa, which follows the seller’s seat rather than yours, is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Deutschland, https://www.lda.bayern.de.
Enclessa has no certification and no audit report to send, so the honest answer to an audit clause is documentation and written responses in the first instance — which is the usual and defensible position for a platform of this size, and it is stated rather than left ambiguous in the agreement.
What Enclessa can provide is specific: the published architecture and data model, the OpenAPI description of the entire API surface, the security page describing measures in the same terms as the Article 32 annex, and answers to a security questionnaire from the enterprise contact.
Both are committed to in § 9 of the agreement and are open to every customer, not only Enterprise: one security questionnaire per calendar year is answered, and an on-site inspection can be required where there is a concrete cause for one, on 30 days’ notice, during business hours, by somebody who is not a competitor and is under a confidentiality obligation.
The boxed passages above are facts that have not been settled yet — a notice period, a transfer position, a subprocessor’s legal seat. They are shown as gaps rather than filled with a plausible sentence, because a procurement answer that turns out to be invented is worse than one that is honestly missing, and because a reviewer can then ask about exactly the right thing. Each is resolved with counsel and replaced here and in the legal documents at the same time.
This page is the paperwork. For the mechanisms behind it, the security page describes encryption, tenant isolation, access control and who at Enclessa can see what. The data processing agreement and the privacy notice are the documents themselves. The status page covers incidents and the recovery position, and anything still unanswered goes to contact.
Create a workspace in a couple of minutes. It is yours at your-team.enclessa.app, hosted in the European Union, with encrypted direct messages from the first one you send.
Open beta. Free plan, no payment card to start.