Skip to main content

Djeed · Trust Center

Built to be inspected.

Methodology in public. Provenance on every governed record. A clear deployment boundary for every surface. No third-party analytics, no advertising pixels, no cross-site tracking, no behavioural profiling. The operational signals we do keep are the minimum needed to run the service well — and inside DjeedX every customer gets an audit trail for activity in their own workspace. Anchor and Gateway use separate knowledge foundations per app, profile, and tenant; nothing connects across those scopes by default.

This page is the official record of how that works. For contractual terms see Privacy, Terms, and the DPA.

The Djeed promise

Pillar 01

No third-party tracking.

No Google Analytics, no advertising pixels, no session-replay tools, no behavioural profiling. The browser ships with one strictly-necessary auth cookie, one bot-protection cookie, and a first-party theme preference. That's it.

Cookie Policy

Pillar 02

Boundary stated per surface.

DjeedX runs in Geneva. Anchor Desk is designed for on-device and sealed operation. Anchor Cloud is being built for a tenant-isolated Swiss workspace. Gateway is isolated per instance. The public website has a separate Cloudflare boundary, including globally replicated KV for submitted leads.

Compare every surface

Pillar 03

Isolation before connection.

Every customer, app, profile, and deployment has its own knowledge foundation and tool registry. Cross-scope sharing is explicit, logged, purpose-limited, and revocable — never an automatic match behind the scenes.

How we audit

Section 01

What we collect, and what we deliberately don't.

Two columns side by side, plain language. The left column lists every signal we collect, where it lives, and how long we keep it. The right column lists categories of data we have decided not to collect.

What we collect

  • Account dataName, email, OAuth identifier, profile image — held by our identity provider, Clerk (EU residency configured).RetentionFor the duration of the account, plus 30 days.
  • Lead-form submissionsFields you complete on the request or express-interest forms. Stored server-side in encrypted Cloudflare KV.RetentionUp to 24 months, or until conversion to an account.
  • Workspace content (DjeedX)Forms, records, attachments, and audit metadata you create in your DjeedX workspace. Tenant-isolated at the database layer.RetentionWorkspace lifetime + 30-day export window after termination.
  • Edge request logsIP, user-agent, request path, status code, timing. Used for service integrity, platform reliability, and capacity planning under GDPR Art. 6(1)(f).Retention30 days, then aggregated.
  • Audit log (DjeedX)Every record create, update, delete, export, and member change. Surfaced back to the workspace admin.RetentionWorkspace lifetime — required for compliance.

What we don't collect

  • Mouse-move heatmaps, click-paths, scroll-depth maps, or any DOM-level instrumentation.
  • Session replay — we run no Hotjar, FullStory, LogRocket, Mouseflow, Smartlook, or equivalent.
  • Third-party analytics — no Google Analytics, no Mixpanel, no Amplitude, no Segment, no cross-site tracking IDs.
  • Advertising pixels — no Meta pixel, no LinkedIn Insight, no Google Ads conversion, no TikTok pixel, no retargeting.
  • Browser fingerprinting — no canvas / WebGL / audio-context fingerprint hashes.
  • Email tracking pixels in transactional mail.
  • Behavioural profiling for marketing personalisation, ad targeting, or any non-operational purpose.

The bottom lineDjeed runs no <script> tag that pings a third-party analytics endpoint on either djeed.com or DjeedX. The performance and privacy benefits compound: lighter pages, no consent banner, no third-party contracts to audit.

Section 02

One trust answer does not fit every surface.

Status, deployment, data, and isolation are stated together. Preview and in-development surfaces are labelled as such; a residency promise on one product is never silently applied to another.

SurfaceStatusDeployment boundaryData in scopeIsolation
djeed.comLiveCloudflare Pages; R2 in the EU jurisdictional ring; KV globally replicatedPublic site content, submitted lead details, and operational rate-limit stateSeparate from customer product workspaces
DjeedXInvite-only betaInfomaniak Public Cloud · Geneva, SwitzerlandWorkspace records, files, graph data, audit metadata, and backupsWorkspace and tenant boundaries in the application and data layers
Anchor DeskPublic preview · in developmentCustomer device; sealed zero-egress mode is a product requirementOnly approved local folders, conversations, memory, models, and toolsSeparate foundation per selected working scope; no cloud attach while sealed
Anchor CloudIn developmentPlanned tenant-isolated Swiss workspace on InfomaniakTenant-approved sources, foundation, routines, and organization toolsSeparate tenant foundation and tool registry; explicit grants only
GatewayLive embedded surfaceInstance-specific; agreed for each tenantThat site's foundation, approved brief, session context, and server-side toolsNo visitor filesystem or terminal access; no cross-site visitor profile
Cloud ServicesScoped deliveryCustomer-selected cloud, data centre, air-gapped environment, or providerDefined in the delivery scope and data-processing termsCustomer-specific architecture and responsibility model

Section 03

Where your data lives.

The two current infrastructure boundaries below are deliberately separated. Your workspace data — the records you create in DjeedX, the audit log, the backups — sits in Geneva, Switzerland, on Infomaniak Public Cloud. Infomaniak is an independent, ethical, Swiss-sovereign cloud and AI provider — renewable-powered, under Swiss data-protection law, and deliberately not a US hyperscaler. Djeed's own AI runs on Infomaniak's sovereign Swiss AI, so the intelligence layer stays in the same jurisdiction as the data. The public website at djeed.com is a separate Cloudflare surface. Its R2 object store uses the EU jurisdictional ring; Cloudflare KV, which stores lead submissions and rate-limit state, is globally replicated and has no per-namespace residency control. Anchor and Gateway boundaries are stated separately in the matrix above.

A modern server panel in a Swiss-sovereign data centre — where DjeedX workspace data is hosted on Infomaniak in Geneva

Side A · your data

DjeedX workspace · Geneva, Switzerland.

Every record you create in DjeedX, every member you invite, every file you upload, every audit-log entry, every backup — all of it lives on Infomaniak Public Cloud in Geneva. Infomaniak is an independent, ethical, Swiss-sovereign cloud and AI provider — renewable-powered and under Swiss data-protection law, not a US hyperscaler. The factory that produces base datasets runs on the same Swiss infrastructure. This is where your real data sits.

  • · Postgres 16 + PostGIS — workspace records, audit log
  • · Neo4j 5 + APOC — graph data, entity relationships
  • · Redis — job queue, session cache
  • · Object storage (CH) — backups, 30-day rotation
  • · Infomaniak hosts the operating system and the network
  • · Sovereign Swiss AI — Djeed's AI runs on Infomaniak, in Switzerland

Side B · the website

djeed.com · Cloudflare, EU jurisdiction.

The public site, methodology pages, and lead-capture forms run on Cloudflare Pages at the European edge. Storage on this side is small and operational: aggregate factory snapshots, lead-form submissions, and rate-limit counters. None of your DjeedX workspace data passes through here.

  • · Cloudflare Pages — djeed.com static + edge functions
  • · R2 (EU jurisdictional ring, Western Europe) — public site snapshots only
  • · KV — lead submissions + rate-limit state (globally replicated; Cloudflare KV has no per-namespace residency option)
  • · Turnstile + WAF — bot protection, request filtering
  • · DjeedX sign-in routes through Cloudflare to the Swiss VM; nothing is stored on this side
                          ┌──────── visitor ────────┐
                          │                          │
                          ▼                          ▼
              ┌── Cloudflare edge (global) ──┐    djeedx.djeed.com sign-in
              │   TLS 1.3 · WAF · Turnstile  │           │
              │   DNS · CDN · Bot mgmt        │          │ (passes through,
              └────────────┬──────────────────┘          │  not stored on CF)
                           │                              │
       SIDE B — website surface (Cloudflare)                │
       ┌─────────────┬──────────────────┐                 │
       ▼             ▼                  ▼                 │
   djeed.com    KV (global)          R2 (EU jurisdiction) │
   Pages        leads + rate-limit   factory stats        │

       SIDE A — your data (Infomaniak Geneva, CH) ◀──────┘
       Infomaniak Public Cloud · Geneva, Switzerland
       ├─ Postgres 16 + PostGIS  (workspace records, audit)
       ├─ Neo4j 5 + APOC         (graph data)
       ├─ Redis                  (job queue)
       ├─ Object storage (CH)    (backups, 30-day rotation)
       └─ Caddy host             (TLS termination)

   Identity:  Clerk (EU residency configured) — clerk.djeed.com
Network connections threading through a data room — the EU/Swiss residency boundary where the website edge and the sovereign workspace meet

Residency is product- and service-specific. DjeedX customer content stays inside its Swiss workspace boundary; public-site lead submissions use globally replicated Cloudflare KV. The applicable processing and transfer terms are documented in Privacy §04.

Section 04

Sub-processors.

The other companies that process personal data on Djeed's behalf, what each one does, and where they sit. Each is bound by a written agreement and processes data only on our documented instructions.

A technician working at a server rack — the staffed, accountable infrastructure operators behind Djeed's Swiss-sovereign hosting
Sub-processorRoleRegionStatus
Cloudflare, Inc.Website surface only: CDN, DNS, R2 (public site snapshots), KV (lead submissions + rate-limit), Turnstile bot protection. Does not process DjeedX workspace data.Global edge (EU/CH primarily for European visitors); R2 bucket created in the EU jurisdictional ring (Western Europe); KV globally replicated (no per-namespace residency).Active
Infomaniak Network SACompute, PostgreSQL, Neo4j, Redis, and CH-resident object storage for DjeedX workspaces. Also the target infrastructure for tenant-isolated Anchor Cloud workspaces as that surface is built.Geneva, SwitzerlandActive
Clerk, Inc.Identity, sessions, organisation managementEU residency configuredActive
Neo4j, Inc.Managed graph database (Aura) — engaged when DjeedX migrates from container Neo4j to managed AuraEUContracted, not yet active
Resend, Inc.Transactional email — engaged when transactional mail is enabledEUContracted, not yet active
Stripe Payments Europe, Ltd.Payment processing — engaged when paid plans are activatedEUContracted, not yet active

Material changes to the sub-processor list are notified to account holders by email at least 14 days before the change takes effect.

Section 05

Security posture.

The technical and organisational safeguards that are in place today. Items are listed only when they are running in production — items in flight are tracked separately in the strategy document and surface here when they ship.

Encryption in transit

TLS 1.3 on every public endpoint. HSTS preload-eligible. No mixed-content paths.

Encryption at rest

AES-256 for databases, object storage, and backups. Keys managed by the underlying provider; rotation is on the provider's schedule.

Tenant isolation

Inside DjeedX, every workspace has its own row-level security boundary at the Postgres layer. Cross-workspace queries are not possible at the database level.

Cross-scope isolation

Anchor and Gateway treat each app, profile, tenant, and deployment as a separate foundation with a separate tool registry. Sharing requires an explicit, logged grant.

Audit log

Every record write inside DjeedX is logged with actor, timestamp, IP, and diff. The log is append-only and surfaced back to workspace admins.

Bot protection

Cloudflare Turnstile gates the public lead-form endpoints. Sign-in attempts are throttled by Clerk.

Backups

Daily backups of Postgres and Neo4j, encrypted at rest, with a 30-day rotation window. Stored in Switzerland alongside primary storage. Restore procedure documented and rehearsed.

Dependency scanning

GitHub Dependabot on the platform monorepo. CI build is non-deployable on a high-severity advisory in a production dependency.

Least-privilege access

Operator access to production is limited to the founder during the private-beta phase. Cloud credentials are stored in chmod-0600 files on the operator workstation, never in the repo, never in chat.

Section 06

Platform integrity signals.

Operational signals we keep to run the service reliably — focused on the platform itself, not on the visitor as an individual. Categories, sources, and what gets flagged.

Web Application Firewall

Cloudflare WAF

Injection attempts (SQL, command, header), known-bad payloads, request-size anomalies — filtered with Cloudflare's managed ruleset.

Bot management

Cloudflare Bot Score + Turnstile

Automated traffic, scraping behaviour, headless-browser fingerprints. Forms fail-closed when Turnstile validation fails.

Rate-limit violations

Cloudflare KV counters + Clerk

Per-IP request floods on /api/leads/* and sign-in. Counters surface to operators; the IP is throttled or blocked at the edge.

Failed-sign-in patterns

Clerk security events

Repeated failed-credential attempts, sign-ins from unusual geographies, OAuth callback anomalies, session-token reuse.

Application-level errors

FastAPI structured logs (DjeedX)

5xx error spikes, slow queries, dramatiq job failures, Postgres connection-pool saturation.

Audit-log anomalies (DjeedX)

Postgres audit_log table

Bulk-delete patterns, export bursts, member-role escalations. Surfaced to the workspace admin in the customer Audit Center (Phase 3) and to operators only on customer report.

Section 07

Vulnerability disclosure.

We welcome reports from security researchers. If you have found a vulnerability, contact us before disclosing publicly — we acknowledge within 72 hours and will work with you on a co-ordinated timeline.

How to report

Email security@djeed.com.

Include reproduction steps, affected URL or endpoint, the impact you believe the issue has, and any suggested mitigation. PGP available on request.

Machine-readable: see /.well-known/security.txt (RFC 9116).

What we ask

  • · No automated scanning that degrades service
  • · No social engineering of staff or customers
  • · No data exfiltration beyond the minimum needed for proof
  • · No public disclosure before we have had time to fix
  • · Good-faith research is not pursued legally — see safe-harbour below
Safe harbourDjeed will not pursue civil or criminal action against security researchers who, in good faith, follow this policy and have not intentionally damaged the service or accessed user data beyond the minimum needed to demonstrate impact.

Section 08

Compliance status.

We name the standards we align to today and the ones we are working toward. Where a certification is not yet held we say so plainly, rather than implying coverage we don't have.

GDPR

Aligned

The Privacy Policy, DPA, and operating practice implement the controller and processor obligations of Regulation (EU) 2016/679. Subject-rights workflow runs through privacy@djeed.com with a 30-day SLA.

Swiss revFADP

Aligned

The Federal Act on Data Protection (revised, in force September 2023) is observed for all Switzerland-resident data. Switzerland is covered by the EU Adequacy Decision (renewed January 2024).

ePrivacy Directive

Aligned

No non-essential cookies, no client-side tracking. Article 5(3) consent is not triggered because there is no storage on or access to user-device data beyond strictly-necessary purposes.

ISO/IEC 27001

Working toward

Annex A self-assessment is on the roadmap post-incorporation. We do not claim certification.

SOC 2

Working toward

Type I readiness assessment planned once the operating entity is incorporated and a multi-engineer team is onboarded. We do not claim certification.

Berkeley Protocol

Methodology-aligned

The Bronze → Silver → Gold pipeline that produces our records is mapped to the Berkeley Protocol on Digital Open Source Investigations — the most rigorous open-source-research standard available. The same chain-of-custody discipline travels across sectors, from a planning team tracking permits across municipalities to a corporate-research team building entity graphs from registries and filings. See the Methodology page.

Section 09

Status and incidents.

Operational status, incident history, and the policy we follow when an incident affects customer data.

Live status

status.djeed.com — coming soon

A public uptime page covering djeed.com, djeedx.djeed.com, and their API endpoints will publish at status.djeed.com. Until it ships, operational issues are posted to the Djeed Beta workspace announcement channel and emailed to affected accounts.

Incident response policy

Notify within 72 hours of confirmed personal-data breach.

For any personal-data breach, we notify the relevant supervisory authority and affected customers within 72 hours of becoming aware, per GDPR Article 33. Post-incident review is published as a public postmortem when remediation is complete.

Talk to a person

Three addresses, one team.

Privacy and data-protection rights: privacy@djeed.com. Vulnerability reports: security@djeed.com. Contractual or commercial questions: legal@djeed.com. We respond within 30 days; usually much sooner.

Living documentThe Trust Center reflects the operating practice of the private beta. Sub-processor list, certification status, and incident history are kept current; material changes are notified to account holders by email at least 14 days before they take effect.