Security & privacy
Look up where your data is
Four questions every security review asks first.
- Where is the content held?
- In European regions, the application in Frankfurt.
- Who processes outside the EU?
- Four services: Clerk, Stripe, Resend, Voyage AI.
- Does the AI train on it?
- No. We do not, and the providers are contractually bound not to either.
- Is there a certificate?
- ISO 27001 and SOC 2 in certification, penetration tests ongoing.
The path of a message
Widget
Leaves the browser over TLS. No third-party fonts, no third-party scripts.
Application
fra1
Checks membership of the workspace.
Database
europe-west3
Conversations, knowledge, accounts. The authoritative copy.
AI agent
Vertex eu
Formulates the answer and names the source.
Semantic search
USA
Only if configured. Receives the knowledge content itself.
Notification
USA
Contains verbatim excerpts from the conversation.
File attachments are held in the storage of the same European region, and the live update runs in europe-west1.
Where the data is held
Nine service providers. Five in the EU, four in the USA.
European Union
5Conversations, knowledge, files and the AI answer.
Google Cloud SQL (PostgreSQL)
Database
Google Cloud Storage
File attachments and logos
Google Firebase Realtime Database
Live update of open conversations
Anthropic (Claude) über Google Vertex AI
Generation of the AI answers
Vercel
Operation and delivery of the application
USA
4Sign-in, payment, email delivery, semantic search.
Clerk
Sign-in and accounts
Stripe
Payments and subscriptions
Voyage AI
Embeddings for the knowledge search, only where configured
Resend
Sending of transactional emails to the team
The wording, as the data processing agreement and the privacy policy also carry it
The content stays in the EU. Conversations, knowledge base and accounts are held in the database region europe-west3 (Frankfurt), file attachments and logos in the file storage of the same region, the live update of open conversations runs in europe-west1, and the AI agent answers from the Vertex multi-region eu; the auxiliary models for subject lines and document analysis run in europe-west1. The region of the file storage was measured on 7 August 2026 against the buckets in use; all the others are stated in the configuration of the deployment.
Four services process outside the EU, namely in the USA: Clerk for sign-in, accounts and sessions, Stripe for payment processing, Resend for sending the team notifications — these contain verbatim excerpts from conversations — and Voyage AI for the embeddings of the semantic search, which receives the knowledge content for that purpose. These transfers are based on the standard contractual clauses of the EU Commission; which version and which impact assessment applies to each provider is recorded in the data processing agreement. The operation of the application itself lies with Vercel, a US corporation; the serving region of this deployment has not been measured and is marked there as an open slot as well.
All nine with purpose and processing region
Service provider
What for
Processing region
- ClerkThird country
Sign-in and accounts
USA — transfer to a third country on the basis of the standard contractual clauses. Name, email address and session data of the team members are transferred.
- StripeThird country
Payments and subscriptions
USA — transfer to a third country on the basis of the standard contractual clauses. The invoicing and payment data of the client are transferred.
- Google Cloud SQL (PostgreSQL)
Database
europe-west3 (Frankfurt) according to the instance configuration in use; measured in the development environment.
- Google Cloud Storage
File attachments and logos
EUROPE-WEST3; measured on 7 August 2026 against the buckets in use. Unlike the other regions, this value is in no configuration in the source code — GCS_UPLOAD_BUCKET states only the name of the bucket.
- Google Firebase Realtime Database
Live update of open conversations
europe-west1 according to the database URL in use; measured in the development environment.
- Anthropic (Claude) über Google Vertex AI
Generation of the AI answers
The support agent runs in the Vertex multi-region eu, the auxiliary models in europe-west1; both values are stated in the configuration of the deployment (CLOUD_ML_REGION and CLOUD_ML_REGION_UTILITY).
- Voyage AIThird country
Embeddings for the knowledge search, only where configured
USA — transfer to a third country on the basis of the standard contractual clauses. The knowledge content itself is transferred, not merely an excerpt of it.
- ResendThird country
Sending of transactional emails to the team
USA — transfer to a third country on the basis of the standard contractual clauses. The notifications are transferred together with the excerpts from conversations they contain.
- Vercel
Operation and delivery of the application
Frankfurt am Main (fra1). The provider is a US corporation, the execution of this deployment takes place in the EU.
Contractual basis per provider: in the data processing agreement.
Encryption, separation, access
- In transit
- All connections run over TLS.
- At rest
- Standard encryption of the Google Cloud services. We do not manage our own keys.
- Tenant separation
- Every access is checked server-side against team membership.
- Access by us
- Only under the four-eyes principle, logged, logs for 30 days.
What the AI does with your content
We do not analyse your content to train our own models. Both providers involved are contractually bound to the same exclusion: the model provider through the data processing terms of Google Cloud, the embedding provider through the terms of use of Voyage AI.
The agent answers from your knowledge base and names the source. If it finds nothing, it hands over to a human. There is no Anthropic account; the models run in the Google Cloud environment.
Deletion and retention periods
- 30 days
- Grace period after the deletion of a workspace, reversible until the last day.
- 7 days
- Retention of the backups. After that, a deleted conversation is gone there too.
- 1 year
- Retention of the operational logs, encrypted in our internal cloud.
- Statutory
- Invoice data under § 147 AO and § 257 HGB, restricted instead of deleted.
Individual conversations and help articles can be deleted in the product at any time.
Report a security vulnerability
Write to us what you found and how it can be reproduced, before you publish it.
info@comlayer.app- Acknowledgement of receipt within 2 working days, then an assessment.
- No legal steps against a report made in good faith that does not extract other people's data.
- On request we will name you once the vulnerability is closed.
Contracts and information
For a data processing agreement, a completed security questionnaire or information under Art. 15 GDPR, an email to info@comlayer.app is enough. No data protection officer has been appointed, because we do not reach the thresholds of § 38 BDSG.
This page summarises our measures and is not a legally conclusive assurance. We make specific commitments by contract. Read the terms.