Compliance & Data Residency¶
Data residency¶
b'nerd is operated exclusively in Germany. All infrastructure, data at rest, and data in transit remains within German data centres at all times. There is no cross-border transfer of customer data to non-EU jurisdictions.
Physical infrastructure (compute nodes, storage, networking) is housed in certified German data centres operated under ISO 27001-compliant procedures. b'nerd does not use hyperscaler public cloud for production workloads.
Certifications¶
| Standard | Status | Scope |
|---|---|---|
| ISO 27001 | Certified | Information security management system covering the b'nerd platform |
| GDPR (EU 2016/679) | Compliant | b'nerd GmbH acts as data processor under Article 28 |
Certification documents are available on request — contact hello@bnerd.com.
GDPR¶
b'nerd GmbH is a German limited company (GmbH) registered in Hamburg and is subject to German and EU data protection law (BDSG + GDPR).
Data controller / data processor split:
- You (the customer) are the data controller for data you store on the platform.
- b'nerd GmbH is the data processor under Article 28 GDPR — we process customer data only to operate the service as specified in the DPA.
Data Processing Agreement (DPA):
A standard DPA compliant with Article 28 GDPR is available on request. To receive a copy or to negotiate a custom DPA, contact hello@bnerd.com or your account manager.
Data subject requests:
If one of your end-users submits an erasure or portability request (Articles 17 and 20), b'nerd can assist with a data export or deletion of the relevant project's resources. Contact hello@bnerd.com with your organization ID and the details of the request.
No US CLOUD Act exposure¶
All infrastructure runs in Germany. b'nerd GmbH is a German entity with no US parent company and no US-hosted infrastructure. Customer data is not subject to US CLOUD Act requests.
Multi-factor authentication¶
Multi-factor authentication (MFA) is available for all accounts and mandatory for admin-role accounts.
| Account type | MFA requirement |
|---|---|
| Admin | Required — TOTP must be enrolled before the dashboard is accessible |
| Member / all other roles | Optional — strongly recommended |
Supported methods:
- TOTP (Time-based One-Time Passwords) — works with any standard authenticator app (Aegis, Authy, 1Password, Google Authenticator, etc.)
- Recovery codes — 16 single-use backup codes generated at enrollment
See the MFA guide for enrollment and account recovery instructions.
Audit logging¶
The platform records all significant write operations (resource creation, modification, deletion) with timestamp, actor account, and outcome. Audit logs are available to organization Admins via the Audit API and the Dashboard under Settings → Audit Log.
Audit log retention: 12 months.
Vulnerability disclosure¶
To report a security vulnerability, email hello@bnerd.com with "SECURITY" in the subject line. We acknowledge reports within one business day and aim to triage within three business days.
Do not disclose vulnerabilities publicly before coordinating with us.