Skip to security content
Back to home

Security & operations

How HansaChat protects company communication.

A concrete account of where data lives, how workspace boundaries work, what is encrypted, how recovery is handled, and when the service operator can access data.

Last updated: August 2026

What this page claims—and what it does not

The controls below describe what is implemented today. HansaChat does not claim an independent security certification or a published penetration-test report.

Report a security concern
Primary application storage
IONOS Cloud in the EU
Encrypted backup copies are also stored in Frankfurt and Stockholm; every location is detailed below.
Workspace boundary
Separate database
Each workspace keeps application data in a physically separate database.
File encryption
AES-256 at rest
Uploaded files use IONOS server-side Object Storage encryption.
Recovery cadence
Every 6 hours
Encrypted Restic backups follow a documented retention schedule.

Data location & isolation

A European operating boundary, made concrete.

HansaChat runs its core service on IONOS Cloud. Account, workspace, and message data is stored in managed MySQL-compatible Database as a Service (DBaaS) infrastructure, while uploaded files are stored separately in IONOS Cloud Object Storage.

How company data moves

Your team

Web and device apps

Clients connect to HansaChat over HTTPS and TLS.

Application

HansaChat service

Authentication, access rules, messaging, and workspace administration.

Storage

IONOS Cloud

Separate workspace databases and encrypted Object Storage for files.

Database isolation by workspace

Each workspace keeps application data in its own physically separate database. Free and demo workspaces may share the underlying managed database service; each paid workspace is provisioned with its own managed database.

Files stored separately

Uploaded files are stored outside the message database in IONOS Cloud Object Storage. Server-side encryption protects objects at rest using AES-256.

Protection & access

Encryption is one layer. Access boundaries matter too.

The service protects data in transit, encrypts uploaded files at rest, hashes passwords, and applies workspace and channel access rules. HansaChat is not end-to-end encrypted: the service operator retains technical access where operation requires it.

Between clients and HansaChat

HTTPS & TLS Encryption

Connections between HansaChat clients and the service use HTTPS and TLS. This protects data while it travels over the network; it is not a claim of end-to-end encryption.

Uploaded files

AES-256 server-side encryption

Uploaded files are stored in IONOS Cloud Object Storage and encrypted at rest using server-side encryption.

IONOS Cloud documents AES-256 for its server-side Object Storage encryption.

Important operational boundary

HansaChat can technically access workspace data.

As the service operator, HansaChat has the technical capability to access workspace data, including emails, messages, files, user records, and memberships. Access is limited to maintenance, troubleshooting, security, abuse prevention, legal compliance, or customer-requested support.

Workspace owners and admins do not automatically gain access to private-channel content or direct messages unless they are members or participants.

Authentication controls

  • Passwords are hashed with bcrypt and automatic salts.
  • Two-factor authentication is available for user accounts.
  • Sessions use encrypted cookies and expire after inactivity.
  • Session identifiers are regenerated after login.

Channel and message visibility

  • Workspace members can discover and join public channels.
  • Private channels require an invitation from an existing member.
  • Admins and owners cannot read a private channel unless they belong to it.
  • Admins and owners cannot read direct messages unless they are a participant.

Recovery & lifecycle

Two recovery layers. Retention is explicit.

IONOS manages recovery for the MariaDB database service. HansaChat also maintains separate encrypted application backups on its own schedule.

Provider-managed database recovery

MariaDB DBaaS with point-in-time recovery

HansaChat uses IONOS Cloud MariaDB Database as a Service (DBaaS). IONOS documents automatic backups retained for seven days and self-service recovery of a database cluster to a selected point in time.

Review IONOS backup documentation Opens in a new tab.

Encrypted Restic Backups

In addition to the provider-managed DBaaS backups, HansaChat creates encrypted and compressed Restic snapshots. They are stored in Frankfurt (Germany) and Stockholm (Sweden); both locations are inside the EU.

Residency note: Both backup locations, Frankfurt and Stockholm, are inside the European Union. Core application storage remains on IONOS Cloud in Germany.

  1. Every 6 hours

    A new encrypted backup snapshot is created.

  2. 7 days

    Every snapshot is retained for the first week.

  3. 30 days

    One daily snapshot is retained after the first week.

  4. Up to 12 months

    Weekly snapshots continue for 12 weeks and monthly snapshots for 12 months.

View the exact backup schedule
  • Backup schedule: every 6 hours.
  • Keep all snapshots for 7 days.
  • Then keep 1 daily snapshot for 30 days.
  • Then keep 1 weekly snapshot for 12 weeks.
  • Then keep 1 monthly snapshot for 12 months.

Workspace retention and deletion

Demo

Deleted after 24 hours.

Free

Remains writable and is deleted after 90 days without a persisted message, with 30-, 7-, and 1-day owner warnings.

Paid

Usable through the paid or trial period. After cancellation takes effect, it is read-only for 90 days and then deleted; successful reactivation restores write access.

Owner-requested deletion is read-only immediately with a 30-day grace period. Workspace databases and uploaded objects are removed by the applicable deletion process; deleted workspace data ages out of encrypted backups according to the schedule above.

Monitoring, privacy & evidence

Operational visibility without advertising trackers.

Logging & Monitoring

HansaChat uses Sentry for logging and monitoring. Operational and security records may include error reports, authentication events, request details, and abuse-prevention signals needed to run and protect the service.

Analytics boundaries

HansaChat does not use third-party advertising trackers. Limited analytics may include browser name, country, and visited pages. IP addresses are not intentionally recorded for analytics, but may appear in security, infrastructure, billing, email-delivery, or error-monitoring records where operation requires them.

GDPR roles and data rights

For customer workspace content, HansaChat generally acts as a processor for the workspace owner or customer. For account administration, billing, security, support, and service operation, HansaChat acts as a controller. Applicable rights include:

  • Access and correction of personal data
  • Erasure and restriction where applicable
  • Data portability: paid workspaces can export every channel as a Slack-compatible archive from the dashboard
  • Objection to certain processing

Verify the underlying policies

Use primary provider documentation and HansaChat policies to check the claims that matter to your rollout.

Published as commitments

HansaChat publishes an availability target, recovery objectives (RPO/RTO), a restore-testing cadence, support response times, and a public status page with incident history. The service level agreement is the authoritative source for all of them.

Responsible disclosure

Found a vulnerability or need a security answer?

Email a clear description and reproduction details to igor@hansa.chat. Reports are investigated directly, and security questions from prospective customers are welcome before rollout.

Email security contact