1. Where Wiiseto runs
- The app, the API and the database run on Amazon Web Services in Zurich, Switzerland. The website runs on Infomaniak in Geneva, Switzerland.
- Files and backups are stored in the European Union (Cloudflare R2, EU jurisdiction).
- All traffic passes through Cloudflare, which protects against attacks and encrypts connections.
- Email is sent through Amazon SES in Zurich, or Frankfurt where needed. Analytics, if you allow them, go to PostHog in the EU.
- AI features, when enabled, send requests to providers in the United States and France. The Sub-processors page has the full list.
2. Encryption
- Every connection is encrypted with TLS, from your browser to Cloudflare and from Cloudflare to our servers.
- Passwords are hashed with bcrypt; we cannot read them.
- Two-factor secrets, backup codes, calendar connection tokens and single sign-on secrets are encrypted in our database with AES-256-GCM.
- Files and backups are encrypted at rest by our storage provider.
- The rest of the database is not encrypted field by field. It is protected by access control on the server.
3. Access control
- Every request is checked on the server: are you a member of this company, and do your role and project permissions allow this action? Anything not allowed is denied.
- Two-factor authentication (authenticator app, email code, backup codes) is available on every plan. Enterprise companies can require single sign-on.
- Each sign-in gets a risk check based on your recent sessions. An unusual sign-in asks for an extra email code and sends you an alert.
- Sign-in and the API are rate limited to slow down guessing and abuse.
- You can see and end your active sessions and trusted devices in your account.
4. Our own access
Only the people who run Wiiseto have access to production. We look at a workspace only to run the service, when you ask us for support, or when the law requires it. We do not browse customer data.
5. Backups and recovery
The database is backed up every night. Backups are kept 7 days on the server and 30 days in EU storage. They are for disaster recovery; we cannot restore a single item you deleted. Deleted items first go to the trash for 30 days.
6. Privacy by design
- Location data is removed from photos.
- Analytics are off until you say yes, mask all text, and never record your screen.
- Public share links can have a password and an expiry date.
- The app works offline from a copy in your browser, which is deleted when you sign out.
7. What we are working on
We prefer to tell you what is not done yet, and that we are working on it:
- Automatic deletion of files when a deleted company is purged. Until then, we do it on request.
- Stricter browser security headers (HSTS), so browsers always refuse an unencrypted connection.
- Self-service export and account deletion, so you no longer need to email us.
- A security certification such as ISO 27001 or SOC 2. We do not hold one today.
- There is no formal uptime commitment unless an order form gives one.
8. Incidents
If a security incident affects your data, we act on it at once and tell your company as soon as possible, and in any case within 72 hours, with what we know and what we are doing. Within 31 days, we send a detailed report of what happened and what we changed. We notify the authorities where the law requires it. Planned maintenance and outages are shown on our status page.
9. Reporting a vulnerability
Write to [email protected]. We acknowledge within 48 hours and give you an update at least every 5 business days until it is fixed. We will not take legal action against good-faith research that:
- does not access, change or delete other people's data beyond what is needed to show the issue;
- does not degrade the service (no denial of service, no spam, no social engineering of our team or customers);
- gives us reasonable time to fix the issue before it is made public.