Security at YOWO7
EU hosting for core systems, encryption, roles, and a zero-knowledge password vault — transparent, without certification fluff.
Four pillars for everyday work
What is built into YOWO7 — from infrastructure to the team vault.
EU data center
Core systems in Frankfurt. Auxiliary services only with safeguards — details in Privacy and Subprocessors.
Encryption
TLS in transit and encryption at rest — as stated in Privacy and the DPA.
Roles & permissions
Viewer, Member, Admin, and Owner control who can do what in the workspace.
Password vault
Zero-knowledge for tool credentials from Team plan — plaintext only in the browser.
Core systems in the EU
Application, database, files, platform email, and AI run on AWS in Frankfurt. Some auxiliary services may involve third-country transfers with an adequacy decision and/or EU Standard Contractual Clauses.
- Core systems exclusively in the EU (Frankfurt)
- Workspace content and AI there
- Auxiliary services and safeguards: Subprocessors
Transparency over blank claims
Where data lives and who helps is documented in Privacy, DPA, and the subprocessor list.
Encryption in transit and at rest
Technical and organisational measures under Art. 32 GDPR: TLS in transit and encryption at rest — as Privacy and the DPA state.
- TLS encryption in transit
- Encryption at rest
- Details in Privacy and DPA
No invented specs
We only repeat what Privacy and the DPA support — without claiming AES or TLS version numbers.
Role-based access control
Four workspace roles: Viewer, Member, Admin, and Owner. Rights apply at workspace, app, and object level — so only the right people write or administer.
- Viewer, Member, Admin, Owner
- Assign roles in Admin
- Fine-grained per app and object
Audit log from Business
Trace security-relevant activity: who changed what, and when. The audit log is part of Business and Enterprise — not Starter or Team.
- From Business plan
- Who, when, what — traceable
- For control and day-to-day compliance
Honest about the plan
Audit log is listed with Business pricing — not marketed as a default for every plan.
Malware scan status on files
Every file in the drive shows a malware scan status. No isolation or quarantine story — just the status the Files app displays.
- Scan status visible per file
- Part of the Files app
- Same wording as on the Files page
Status, not speculation
The status sits on the file — without an extra service and without invented quarantine.
Password vault with zero-knowledge
Share tool credentials in the workspace: encryption only in the browser. The server stores ciphertext — never plaintext. From Team plan.
- Zero-knowledge: plaintext only in the browser
- From Team plan
- No Public API and no MCP for the vault
Sign-in, sessions, and password
Protected login, sessions in the app, and change or reset password in your profile — without extra IdP marketing.
- Login and protected sessions
- Change password in profile
- Reset password when needed
Legal & evidence
GDPR day-to-day means DPA, subprocessors, and a clear privacy policy — not blank compliance and not ISO/SOC2 claims.
Frequently asked questions about security
Core systems (application, database, files, platform email, AI) run in the EU on AWS Frankfurt. Some auxiliary services such as payments, captcha, calendar OAuth, or push may involve third-country transfers with an adequacy decision and/or EU Standard Contractual Clauses. Details: Privacy and Subprocessors.
With TLS in transit and encryption at rest — as Privacy and the DPA describe. We do not claim additional algorithm or version numbers.
Yes. In the Files app every file shows a malware scan status. More on the Files page.
YOWO7 is designed for GDPR compliance. What matters is the public DPA at /dpa, the subprocessor list, and the privacy policy — not a blank compliance claim.
From Business. Starter and Team do not include the audit log.
Password and notes are encrypted only in the browser. The server stores ciphertext — never plaintext, not even for YOWO7. The vault is included from Team plan.
Viewer, Member, Admin, and Owner. You assign roles in Admin and control access in the workspace.
No. We do not list ISO or SOC2 certifications. Instead: EU hosting for core systems, TOMs in Privacy/DPA, and public subprocessors.
You sign in with your account. Sessions run protected in the app. Change password in your profile; reset when needed.
DPA at /dpa, subprocessors at /subprocessors, privacy at /privacy.
Security is part of YOWO7.
Start in the workspace — with EU hosting, roles, and clear evidence instead of certification fluff.
Get startedDPA, subprocessors, and privacy are publicly linked.