Skip to content

Trust centre

The answers your legal team will ask for

Enclessa is in open beta, and the trust centre holds the documents and answers a buyer’s legal team asks for: the controller and processor relationship, the Article 28 data processing agreement and how to get it, the subprocessor list and how changes are notified, where the service is hosted and whether data leaves the European Union, how a data subject request is handled, retention and deletion, breach notification, and the export path out. Enclessa holds no ISO 27001, SOC 2, HIPAA or comparable certification and has had no external security audit, which is stated first because it is the answer that ends some evaluations.

Open betaThe platform is being built in the open, so parts of it are not there yet, behaviour changes between releases, and no availability figure is committed while it is in beta. What is still being built.

What Enclessa does not hold

If a certification is a procurement gate for your organisation, the answer here is no and you should stop reading. Enclessa would rather be ruled out in the first minute than in the sixth week.

No ISO 27001

Enclessa holds no ISO 27001 certification and no Statement of Applicability, and there is no certification body engaged.

No SOC 2

There is no SOC 2 Type I or Type II report, no auditor engaged, and no observation window under way.

No HIPAA, no BSI C5, no TISAX

Enclessa holds no sector or national certification of any kind, and signs no business associate agreement.

No external security audit

The cryptographic library Enclessa uses has been audited independently. Enclessa’s own implementation has not been through a third-party security audit or a penetration test.

No published pen-test report

There is no report to share, because no test has been commissioned. A questionnaire asking for one gets that answer rather than a deflection.

What exists instead

Published detail a reviewer can check: the architecture, the data model and the whole API surface are documented, the encryption is an IETF standard through an audited open-source library, and tenant isolation is proven by a generated probe suite that fails the build if it regresses. That is evidence, and it is not a certificate.

At a glance

Release stage
Open beta
Certifications held
None
External security audit
Not performed
Role for customer content
Processor; you are the controller
Data processing agreement
Part of the terms; draft pending counsel
Hosting
One European Union region, German seller
Data export
Full organisation export, open formats, any time

Who is the controller and who is the processor?

For everything your organisation puts into the platform — messages, files, task boards, time records, personnel data — your organisation is the controller and Enclessa is the processor acting on your documented instructions. Your organisation decides why the data is there, how long it stays and who may see it; Enclessa provides the controls and carries them out.

For its own relationship with you, Enclessa is the controller: your account, billing records, support correspondence and this website. Those are governed by the privacy notice rather than by the processing agreement.

This split is why no vendor can hand you compliance as a product. Enclessa supplies the processing agreement, the security measures, the export and the deletion; the lawful basis, the retention decisions and the transparency you owe your own staff remain yours.

How do I get a data processing agreement?

The Article 28 data processing agreement forms part of the terms of service and applies from the moment your organisation uses Enclessa. No separate signature is required unless your organisation requires one, in which case a signed counterpart is issued on request through the enterprise contact.

Every provider fact in the text is settled and the document is published in full. What it has not had is a review by counsel, which is stated rather than implied: the positions and the numbers below are the operator’s own and are binding, and the drafting around them has not been through an external pass.

[[ State the turnaround committed to for a signed counterpart, and whether customer paper is accepted or only the Enclessa agreement. The route itself is settled and stated above. ]]

  • Covers subject matter, duration, nature and purpose, and the categories of data and data subject
  • Processing only on the controller’s documented instructions, with a duty to flag an unlawful one
  • Confidentiality obligations on everybody authorised to process
  • The Article 32 security measures, reproduced as an annex kept in step with the security page
  • Subprocessor terms, assistance with data subject rights, breach notification, and deletion or return at the end

Who are the subprocessors, and how are changes notified?

Enclessa engages third parties for hosting, transactional email, payment processing and the delivery of push notifications. Each is bound by data protection terms no weaker than those Enclessa owes you, and Enclessa remains fully liable to you for what they do.

The authoritative list lives in the annex of the data processing agreement and is mirrored in the privacy notice. Enclessa commits to keeping those two identical, because a divergence between them is the first thing a competent reviewer checks and the fastest way to lose an evaluation.

There are 6: netcup GmbH (Karlsruhe, Germany), Mollie B.V. (Amsterdam, Netherlands), Apple Distribution International Ltd. (Cork, Ireland), Google Ireland Limited (Dublin, Ireland), OpenAI Ireland Ltd. (Dublin, Ireland), Infomaniak Network SA (Geneva, Switzerland). Each row of the annex carries the purpose and the Chapter V safeguard alongside the name. Error and uptime monitoring appears nowhere on that list because it is not outsourced — the telemetry runs on Enclessa's own infrastructure.

The authorisation is general rather than specific: you approve the practice in advance, and Enclessa gives at least 30 days’ notice in text form before engaging a new subprocessor or replacing an existing one. Within that period you may object on a substantive data protection ground, and if the objection cannot be resolved you may terminate at the point the change would take effect. That is § 6 (2) of the agreement, not a policy statement.

Where is the data hosted, and does any of it leave the EU?

The hosted service runs in a single European Union region and the seller is a company established in Germany. There is no choice of country within the region on the standard plans, and Enclessa does not imply a region picker exists.

Where a named country is a requirement — which happens in parts of the public sector and in healthcare — the answer is a dedicated deployment of the same hosted service in a region you name, operated and updated by Enclessa. That is the Enterprise arrangement. It is not self-hosting, the software is never handed over, and it is quoted rather than listed.

Two things do leave the EU, and both are named in the privacy notice rather than left to be discovered. Push notifications reach Apple and Google, carrying the device token and the title and sender line — never the body of an end-to-end encrypted message — under the EU-US Data Privacy Framework or, failing that, standard contractual clauses. Email is dispatched through mail servers in Switzerland, which the European Commission has held adequate under Article 45. Nothing else does: the platform’s content, files and databases sit in datacentres in Germany, there is no error-reporting vendor, and support access is by Enclessa staff to that same infrastructure.

How is a data subject request handled?

When one of your people exercises a right — access, rectification, erasure, restriction, portability or objection — your organisation is the controller and owes the response within the statutory deadline. Enclessa’s role is to make finding and extracting the data fast enough that the deadline is comfortable rather than tight.

The People module produces a data-subject export assembling what the platform holds about one person, and an organisation-wide export is available at any time in open formats. Enclessa assists with a request routed through the data protection contact rather than requiring it to go through general support.

One limit is architectural and cannot be engineered away: content in end-to-end encrypted conversations is stored as ciphertext for which Enclessa holds no key, so Enclessa cannot produce it in readable form for any request, from anybody. Managed channels are readable and are covered normally.

Assistance requests are answered within ten working days, and urgent ones without undue delay — § 7 (3) of the agreement. The address is privacy@enclessa.app.

How long is data kept, and what happens when we leave?

Retention is configurable per organisation and the default keeps data rather than deleting it, so nothing disappears because a setting was never visited. Finer-grained retention per team and per channel is planned work and is not available today.

On termination you export everything first — that path is always open and does not require a support ticket or a negotiation — and the organisation is then deleted. Deletion is a resumable purge that derives its scope from the database schema rather than from a hand-maintained list of things to remove, which is what makes it complete rather than approximate. Object storage is cleared with it.

Statutory retention duties override deletion for the records they cover: under German commercial and tax law certain billing and accounting records must be kept for a defined period regardless of a deletion request, and those are retained for that purpose alone.

The periods are fixed rather than discretionary. Your data stays exportable for 30 days after the contract ends; Enclessa then deletes it, backups included, within a further 30 days. The one category that outlives that is invoices and accounting records, kept for eight years under § 257 (4) HGB and § 147 (3) AO as applicable from 2025 — blocked from any other processing in the meantime and deleted once the period runs out.

What happens if there is a breach?

A personal data breach is handled to the statutory timetable rather than to a marketing one. As processor, Enclessa notifies the affected controller without undue delay after becoming aware, with what is known at the time rather than waiting for a complete picture — a first notice that says "we do not yet know the scope" is more useful than a complete one that arrives three days later.

The notification carries the nature of the breach, the categories and approximate number of records and data subjects concerned so far as known, the likely consequences, and the measures taken or proposed. Your organisation, as controller, decides whether the supervisory authority and the affected individuals must be told.

The deadline is a number, not a phrase: § 8 (1) of the agreement commits Enclessa to notifying the affected controller within 24 hours of becoming aware, and to filling in what was not known at first afterwards rather than delaying the first notice.

Breach correspondence runs through security@enclessa.app. The supervisory authority competent for Enclessa, which follows the seller’s seat rather than yours, is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Deutschland, https://www.lda.bayern.de.

What audit and assurance evidence is available?

Enclessa has no certification and no audit report to send, so the honest answer to an audit clause is documentation and written responses in the first instance — which is the usual and defensible position for a platform of this size, and it is stated rather than left ambiguous in the agreement.

What Enclessa can provide is specific: the published architecture and data model, the OpenAPI description of the entire API surface, the security page describing measures in the same terms as the Article 32 annex, and answers to a security questionnaire from the enterprise contact.

Both are committed to in § 9 of the agreement and are open to every customer, not only Enterprise: one security questionnaire per calendar year is answered, and an on-site inspection can be required where there is a concrete cause for one, on 30 days’ notice, during business hours, by somebody who is not a competitor and is under a confidentiality obligation.

Why parts of this page are visibly unfinished

The boxed passages above are facts that have not been settled yet — a notice period, a transfer position, a subprocessor’s legal seat. They are shown as gaps rather than filled with a plausible sentence, because a procurement answer that turns out to be invented is worse than one that is honestly missing, and because a reviewer can then ask about exactly the right thing. Each is resolved with counsel and replaced here and in the legal documents at the same time.

The rest of the evidence

This page is the paperwork. For the mechanisms behind it, the security page describes encryption, tenant isolation, access control and who at Enclessa can see what. The data processing agreement and the privacy notice are the documents themselves. The status page covers incidents and the recovery position, and anything still unanswered goes to contact.

Questions

Procurement and data protection questions

Does Enclessa have ISO 27001 or SOC 2?

No. Enclessa holds no ISO 27001, SOC 2, HIPAA or comparable certification, has no auditor or certification body engaged, and has had no external security audit or penetration test. If a certification is a procurement gate for your organisation, Enclessa is not a fit today and says so rather than describing one as in progress.

How do I get a data processing agreement with Enclessa?

The Article 28 data processing agreement forms part of the terms of service and applies as soon as your organisation uses Enclessa, so nothing has to be requested for it to be in force. Where your organisation requires a signed counterpart, it is issued on request through the enterprise contact. The current text is a draft pending review by counsel and is published in that state with its unresolved clauses visibly marked.

Is Enclessa the controller or the processor of my data?

Both, for different data. For everything your organisation puts into the platform — messages, files, time records, personnel data — your organisation is the controller and Enclessa is the processor acting on your documented instructions. For your account, billing and support correspondence, Enclessa is the controller and its privacy notice governs.

Does any Enclessa data leave the European Union?

The hosted service runs in a single European Union region and the seller is a German company. The complete position on transfers, including support access and email delivery, is being confirmed and is published on the trust centre with the unresolved parts visibly marked rather than answered with an assumption.

Can I get all my data out of Enclessa if we leave?

Yes, at any time and in open formats, without a support ticket or a negotiation. An organisation can export everything the platform holds for it, the data model is documented and the whole API is described by an OpenAPI document. After export, deletion runs as a resumable purge that derives its scope from the schema rather than a hand-maintained list, and clears object storage with it.

Can Enclessa produce my encrypted messages if legally compelled?

No. Direct messages and group direct messages are end-to-end encrypted and Enclessa holds no key that opens them, so it cannot produce their content for anybody — a customer, a regulator or a court. Managed channels are readable by the server by design and would be covered by a lawful order. Enclessa will not build covert access to encrypted rooms; the only route it would ever take is a compliance recipient visible to everybody in the room.

Encrypted collaboration, hosted in Europe.

Create a workspace in a couple of minutes. It is yours at your-team.enclessa.app, hosted in the European Union, with encrypted direct messages from the first one you send.

Open beta. Free plan, no payment card to start.