Trust & security
Where the data runs, who can touch it, and what happens when something breaks. Sober, no marketing.
The main thing first
The operator of Munwyn never sees the content of thoughts — private or company.
Everything else on this page is the set of technical and organisational measures that keeps this true in practice.
Where the data runs
The munwyn.app application, the database and the search index run on a server in Vienna (netcup GmbH), inside the EU. Backups stay in the EU.
The only exception is AI inference (see subprocessors below) — and even that can be kept in the EU: Council Sovereign includes EU inference, and Council Direct solves it with the company’s own EU profile.
Encryption
- All data in transit goes over TLS.
- Sensitive keys (for example company API keys for Council Direct) are stored encrypted on the server; they are decrypted only at the moment of use.
- Card numbers never reach us — payments are processed by Stripe.
Backups and recovery
- Daily backups of the database and attachments.
- Target RPO (data loss at most): 24 hours.
- Target RTO (longest outage during recovery): 12 hours.
- We regularly test restoring from backup — a backup that has never been restored is not a backup.
- Continuity with no lock-in: a company admin can download the company mind as an export (ZIP) at any time; every export shows up in the company audit log.
- A company never disappears overnight: end of payment = 30 days read-only + 60 days for export; a deleted founder account = the company waits half a year for a new owner to take over right in the app.
Access
- Administrator access to the infrastructure requires two-factor authentication (2FA).
- The principle of least privilege applies: every access only in the scope the work requires.
- We keep a security log: who accessed production systems, when and why.
Subprocessors
| Subprocessor | Purpose | Where | Safeguards |
|---|---|---|---|
| netcup GmbH | application and database hosting | EU (Vienna) | data processing agreement, EU data centre |
| Anthropic | AI inference | USA | SCC; ISO 27001, ISO/IEC 42001, SOC 2 Type II |
| Stripe | payments | EU/USA | SCC; PCI DSS — card numbers never reach us |
| Resend | transactional email | USA | SCC |
| Active24 | hosting of the munwyn.com website | EU (Czechia) | the website carries no thought content |
| Umami (self-hosted) | website analytics | our server, EU | runs on our own server, cookie-free — no third party |
We announce subprocessor changes to administrators by email 30 days in advance; the controller has the right to object. The current version of the list always lives here.
Incident notification
We notify affected controllers of a personal data breach without undue delay, and at the latest within 72 hours of becoming aware of it, as the GDPR requires. On Council Pro and above the deadline is contractually shortened to 24 hours.
The notification covers the nature of the incident, the likely scope, the measures taken and recommendations for the controller.
AI Act — Article 50
Everything written by AI in Munwyn carries a visible label in the app and a machine-readable marking in the data (Article 50 of Regulation (EU) 2024/1689). The company probe report is AI output and is labelled as such.
The detailed breakdown of features, models and labelling: How we use AI.
Contact
Security, incidents, questions about this page: . Personal data processing for companies is covered by the Data Processing Agreement (DPA).
Last updated: 22 August 2026 · This page is a summary of technical and organisational measures (TOMs); it is not a legal opinion.