Security.

KNTRA reads documents whose confidentiality is the point. The security model is built on separation rather than policy: one customer, one stack, one database. There is no shared data store a query could cross, because there is no shared anything.

What holds today

Each customer runs on their own application stack with their own database, on infrastructure in Germany that we operate ourselves. Passwords are stored as Argon2id hashes. Sessions live on the server, rotate on use, and a revoked session stops working at once. Retention for completed checks is configurable per customer, and every deletion of a check is recorded by a database trigger that application code cannot bypass. Backups are encrypted with AES-256 before they leave the machine. Transport is TLS throughout.

The reading step, named plainly

One step of a check, the reading of the documents by a language model, currently runs with a model provider outside the EU, configured for zero retention and zero training. We name this here because you would find it anyway, and finding it should not cost you a meeting.

Documents

Contractual and technical documentation is handed out per customer rather than posted as marketing. One line to contact@kntra.de with your name and firm is enough; you will hear back the same day.

  • Security overviewthis page
  • Data processing agreement (Art. 28 GDPR)on request
  • Sub-processor liston request
  • Technical and organisational measureson request