You know where your data lives.
Most CRM security pages say "enterprise-grade protection" and move on. We wrote ours concretely: which country your data sits in, who can reach it, how we track which record was changed by whom — and which third parties touch your data, every one by name and country.
The foundation of the architecture.
A separate database per customer
Every customer runs in its own separate database. Not a "company ID" filter in a shared table — separation at the database level, not an application setting. One exception we state openly: the application's technical error logs are kept in a single table shared by all customers.
Hosted in the EU, stated openly
The database is in Helsinki (Finland), the files you upload are in Frankfurt, and database backups are in Falkenstein — all three inside the European Union. We have no component in Turkey and no region-selection feature. Seen from Turkey this is a transfer abroad under Article 9 of KVKK; we establish the basis for that transfer together with you during the contract process.
Field-level audit trail
A separate history row is kept for every changed field — who, when, the old value, the new value. It is on by default across every object that ships in a standard install; you do not need to enable it.
Recycle bin
Deletion is soft deletion: the record does not leave the database at once, it moves to the recycle bin and stays there for 30 days. We have not measured who can restore from the bin, or whether a separate individual or bulk restore operation exists; we promise no restore capability here. Permanent deletion is a separate permission; an ordinary user cannot destroy a record irreversibly.
Access, identity and the third parties that touch your data
| Control or party | How and where it works |
|---|---|
| Two-factor authentication (2FA) | On by default for every user. The default method is an email code; an authenticator app is also supported (set up with a QR code, backup codes). |
| API authentication | OAuth2; tokens are stored hashed on disk, scope restrictions are actually enforced server-side, and the separation between customer databases is tested. |
| Roles and sharing | Record visibility is controlled with role-based access and sharing rules; field-level hiding is supported. |
| Brute-force protection | Login attempts are limited both per user and per IP address (10 attempts in 15 minutes), and two-factor authentication allows 5 attempts. The counters are kept atomically. |
| Rate limiting | The mechanism is in place: once a limit is exceeded the request is rejected with a 429 and a Retry-After header. Usage analytics show you how many requests each integration is making. We have no published fixed quota figure. |
| Encryption in transit | All traffic runs over TLS. Passwords are stored with PBKDF2-SHA256; two-factor authentication secrets, backup codes and integration credentials are encrypted at rest. Encryption at rest is not applied to the whole database — we do not claim that. |
| Backups | An automatic backup every six hours, integrity-tested, retained for 30 days. Backups are copied to a separate country (Germany); in a restore drill 239 of 239 tables and all 438,817 rows came back complete. |
| Subprocessor — Cloudflare, Inc. | Content delivery network, TLS termination, web application firewall and bot protection · the edge server nearest the visitor, company in the United States. It is in the path of every request and the TLS connection terminates at the edge rather than at the hosting server, so data in transit and the visitor's IP are processed at that layer. No content is stored there. The requests we measured went through EU edge nodes (Amsterdam from Turkey, Stockholm from Helsinki); the node is chosen by proximity to the visitor and is not fixed. |
| Subprocessor — Hetzner | Application server and database · Helsinki, Finland (EU) |
| Subprocessor — Hetzner Storage Box | Database backups · Falkenstein, Germany (EU) |
| Subprocessor — DigitalOcean Spaces | Files and media you upload · Frankfurt, Germany (EU) |
| Subprocessor — Amazon SES | Delivery of system email · Frankfurt, Germany (EU) |
| Subprocessor — Sentry | Application error monitoring · Germany (EU). Configured not to send personal data. |
| Subprocessor — Anthropic (Claude) | The Rapi AI assistant, only if you top up credit and enable it · United States — an Article 9 KVKK transfer |
| Subprocessor — Meta Platforms Ireland Ltd. | WhatsApp Business and Instagram messaging, only if you connect those channels · Ireland, with onward transfer to the United States. Message content and the other party's number or account pass through Meta's infrastructure. |
Where the legal counterpart of this page lives
Every technical statement on this page has a legal counterpart, and we wrote those out one by one on separate pages.
The full list of parties that touch your data is in the subprocessor table above; who each transfer goes to, to which country, and on what legal basis is set out one by one in Sections 8 and 13 of our Privacy Policy. The obligations we take on contractually, and the limits of each one, are on the Terms of Service page. Our KVKK Privacy Notice covers the notice we give for data that reaches us through the forms on this site.
During an enterprise evaluation, the same team that builds the product fills in your security assessment forms; if you ask about something beyond this page, we answer it in writing.
What each plan covers, on one page
Three tiers, a scope table and separately priced items — with the numbers. Scope and any setup fee are worked out in the discovery call and shared in writing.
We publish the figures rather than asking you to request them.
Frequently asked security questions.
Where exactly is our data kept?
Are you GDPR compliant?
Do you sign a data processing agreement (DPA)?
Where does the Rapi AI assistant send our data?
Can another customer see our data?
Can Rapitek staff reach our data?
Can we see who changed what?
Will you tell us if there is a data breach?
Do you hold a security certification?
Do you give a written uptime commitment?
Have you had an independent penetration test?
Can a record deleted by mistake be recovered?
What happens to an employee's data when they leave?
Can we get our data whenever we want?
Who answers support requests?
Can you support our teams in other countries?
Ask our team your security questions.
We fill in enterprise buyers' security assessment forms and walk through the architecture on a screen share. A technical conversation, not a sales call.
The team that builds the product answers your questions
