Security & operations
How HansaChat protects company communication.
A concrete account of where data lives, how workspace boundaries work, what is encrypted, how recovery is handled, and when the service operator can access data.
Last updated: August 2026
What this page claims—and what it does not
The controls below describe what is implemented today. HansaChat does not claim an independent security certification or a published penetration-test report.
Report a security concern- Primary application storage
- IONOS Cloud in the EU
- Encrypted backup copies are also stored in Frankfurt and Stockholm; every location is detailed below.
- Workspace boundary
- Separate database
- Each workspace keeps application data in a physically separate database.
- File encryption
- AES-256 at rest
- Uploaded files use IONOS server-side Object Storage encryption.
- Recovery cadence
- Every 6 hours
- Encrypted Restic backups follow a documented retention schedule.
Data location & isolation
A European operating boundary, made concrete.
HansaChat runs its core service on IONOS Cloud. Account, workspace, and message data is stored in managed MySQL-compatible Database as a Service (DBaaS) infrastructure, while uploaded files are stored separately in IONOS Cloud Object Storage.
How company data moves
Your team
Web and device apps
Clients connect to HansaChat over HTTPS and TLS.
Application
HansaChat service
Authentication, access rules, messaging, and workspace administration.
Storage
IONOS Cloud
Separate workspace databases and encrypted Object Storage for files.
Database isolation by workspace
Each workspace keeps application data in its own physically separate database. Free and demo workspaces may share the underlying managed database service; each paid workspace is provisioned with its own managed database.
Files stored separately
Uploaded files are stored outside the message database in IONOS Cloud Object Storage. Server-side encryption protects objects at rest using AES-256.
Protection & access
Encryption is one layer. Access boundaries matter too.
The service protects data in transit, encrypts uploaded files at rest, hashes passwords, and applies workspace and channel access rules. HansaChat is not end-to-end encrypted: the service operator retains technical access where operation requires it.
Between clients and HansaChat
HTTPS & TLS Encryption
Connections between HansaChat clients and the service use HTTPS and TLS. This protects data while it travels over the network; it is not a claim of end-to-end encryption.
Uploaded files
AES-256 server-side encryption
Uploaded files are stored in IONOS Cloud Object Storage and encrypted at rest using server-side encryption.
IONOS Cloud documents AES-256 for its server-side Object Storage encryption.
Important operational boundary
HansaChat can technically access workspace data.
As the service operator, HansaChat has the technical capability to access workspace data, including emails, messages, files, user records, and memberships. Access is limited to maintenance, troubleshooting, security, abuse prevention, legal compliance, or customer-requested support.
Workspace owners and admins do not automatically gain access to private-channel content or direct messages unless they are members or participants.
Authentication controls
- Passwords are hashed with bcrypt and automatic salts.
- Two-factor authentication is available for user accounts.
- Sessions use encrypted cookies and expire after inactivity.
- Session identifiers are regenerated after login.
Channel and message visibility
- Workspace members can discover and join public channels.
- Private channels require an invitation from an existing member.
- Admins and owners cannot read a private channel unless they belong to it.
- Admins and owners cannot read direct messages unless they are a participant.
Recovery & lifecycle
Two recovery layers. Retention is explicit.
IONOS manages recovery for the MariaDB database service. HansaChat also maintains separate encrypted application backups on its own schedule.
Provider-managed database recovery
MariaDB DBaaS with point-in-time recovery
HansaChat uses IONOS Cloud MariaDB Database as a Service (DBaaS). IONOS documents automatic backups retained for seven days and self-service recovery of a database cluster to a selected point in time.
Encrypted Restic Backups
In addition to the provider-managed DBaaS backups, HansaChat creates encrypted and compressed Restic snapshots. They are stored in Frankfurt (Germany) and Stockholm (Sweden); both locations are inside the EU.
Residency note: Both backup locations, Frankfurt and Stockholm, are inside the European Union. Core application storage remains on IONOS Cloud in Germany.
-
Every 6 hours
A new encrypted backup snapshot is created.
-
7 days
Every snapshot is retained for the first week.
-
30 days
One daily snapshot is retained after the first week.
-
Up to 12 months
Weekly snapshots continue for 12 weeks and monthly snapshots for 12 months.
View the exact backup schedule
- Backup schedule: every 6 hours.
- Keep all snapshots for 7 days.
- Then keep 1 daily snapshot for 30 days.
- Then keep 1 weekly snapshot for 12 weeks.
- Then keep 1 monthly snapshot for 12 months.
Workspace retention and deletion
Demo
Deleted after 24 hours.
Free
Remains writable and is deleted after 90 days without a persisted message, with 30-, 7-, and 1-day owner warnings.
Paid
Usable through the paid or trial period. After cancellation takes effect, it is read-only for 90 days and then deleted; successful reactivation restores write access.
Owner-requested deletion is read-only immediately with a 30-day grace period. Workspace databases and uploaded objects are removed by the applicable deletion process; deleted workspace data ages out of encrypted backups according to the schedule above.
Monitoring, privacy & evidence
Operational visibility without advertising trackers.
Logging & Monitoring
HansaChat uses Sentry for logging and monitoring. Operational and security records may include error reports, authentication events, request details, and abuse-prevention signals needed to run and protect the service.
Analytics boundaries
HansaChat does not use third-party advertising trackers. Limited analytics may include browser name, country, and visited pages. IP addresses are not intentionally recorded for analytics, but may appear in security, infrastructure, billing, email-delivery, or error-monitoring records where operation requires them.
GDPR roles and data rights
For customer workspace content, HansaChat generally acts as a processor for the workspace owner or customer. For account administration, billing, security, support, and service operation, HansaChat acts as a controller. Applicable rights include:
- Access and correction of personal data
- Erasure and restriction where applicable
- Data portability: paid workspaces can export every channel as a Slack-compatible archive from the dashboard
- Objection to certain processing
Verify the underlying policies
Use primary provider documentation and HansaChat policies to check the claims that matter to your rollout.
Published as commitments
HansaChat publishes an availability target, recovery objectives (RPO/RTO), a restore-testing cadence, support response times, and a public status page with incident history. The service level agreement is the authoritative source for all of them.
Responsible disclosure
Found a vulnerability or need a security answer?
Email a clear description and reproduction details to igor@hansa.chat. Reports are investigated directly, and security questions from prospective customers are welcome before rollout.