Security

Security at YOWO7

EU hosting for core systems, encryption, roles, and a zero-knowledge password vault — transparent, without certification fluff.

Four pillars for everyday work

What is built into YOWO7 — from infrastructure to the team vault.

EU data center

Core systems in Frankfurt. Auxiliary services only with safeguards — details in Privacy and Subprocessors.

Encryption

TLS in transit and encryption at rest — as stated in Privacy and the DPA.

Roles & permissions

Viewer, Member, Admin, and Owner control who can do what in the workspace.

Password vault

Zero-knowledge for tool credentials from Team plan — plaintext only in the browser.

Core systems in the EU

Application, database, files, platform email, and AI run on AWS in Frankfurt. Some auxiliary services may involve third-country transfers with an adequacy decision and/or EU Standard Contractual Clauses.

  • Core systems exclusively in the EU (Frankfurt)
  • Workspace content and AI there
  • Auxiliary services and safeguards: Subprocessors

Transparency over blank claims

Where data lives and who helps is documented in Privacy, DPA, and the subprocessor list.

Encryption in transit and at rest

Technical and organisational measures under Art. 32 GDPR: TLS in transit and encryption at rest — as Privacy and the DPA state.

  • TLS encryption in transit
  • Encryption at rest
  • Details in Privacy and DPA

No invented specs

We only repeat what Privacy and the DPA support — without claiming AES or TLS version numbers.

Role-based access control

Four workspace roles: Viewer, Member, Admin, and Owner. Rights apply at workspace, app, and object level — so only the right people write or administer.

  • Viewer, Member, Admin, Owner
  • Assign roles in Admin
  • Fine-grained per app and object

Audit log from Business

Trace security-relevant activity: who changed what, and when. The audit log is part of Business and Enterprise — not Starter or Team.

  • From Business plan
  • Who, when, what — traceable
  • For control and day-to-day compliance

Honest about the plan

Audit log is listed with Business pricing — not marketed as a default for every plan.

Malware scan status on files

Every file in the drive shows a malware scan status. No isolation or quarantine story — just the status the Files app displays.

  • Scan status visible per file
  • Part of the Files app
  • Same wording as on the Files page

Status, not speculation

The status sits on the file — without an extra service and without invented quarantine.

Password vault with zero-knowledge

Share tool credentials in the workspace: encryption only in the browser. The server stores ciphertext — never plaintext. From Team plan.

  • Zero-knowledge: plaintext only in the browser
  • From Team plan
  • No Public API and no MCP for the vault

Sign-in, sessions, and password

Protected login, sessions in the app, and change or reset password in your profile — without extra IdP marketing.

  • Login and protected sessions
  • Change password in profile
  • Reset password when needed

GDPR day-to-day means DPA, subprocessors, and a clear privacy policy — not blank compliance and not ISO/SOC2 claims.

Frequently asked questions about security

Core systems (application, database, files, platform email, AI) run in the EU on AWS Frankfurt. Some auxiliary services such as payments, captcha, calendar OAuth, or push may involve third-country transfers with an adequacy decision and/or EU Standard Contractual Clauses. Details: Privacy and Subprocessors.

With TLS in transit and encryption at rest — as Privacy and the DPA describe. We do not claim additional algorithm or version numbers.

Yes. In the Files app every file shows a malware scan status. More on the Files page.

YOWO7 is designed for GDPR compliance. What matters is the public DPA at /dpa, the subprocessor list, and the privacy policy — not a blank compliance claim.

From Business. Starter and Team do not include the audit log.

Password and notes are encrypted only in the browser. The server stores ciphertext — never plaintext, not even for YOWO7. The vault is included from Team plan.

Viewer, Member, Admin, and Owner. You assign roles in Admin and control access in the workspace.

No. We do not list ISO or SOC2 certifications. Instead: EU hosting for core systems, TOMs in Privacy/DPA, and public subprocessors.

You sign in with your account. Sessions run protected in the app. Change password in your profile; reset when needed.

DPA at /dpa, subprocessors at /subprocessors, privacy at /privacy.

Security is part of YOWO7.

Start in the workspace — with EU hosting, roles, and clear evidence instead of certification fluff.

Get started

DPA, subprocessors, and privacy are publicly linked.