Security & data protection
Where your data lives, how we protect it, and how to reach us about security.
Where your data lives
The GrantCortex application and its database run entirely within the European Union, in Hetzner Cloud’s Helsinki (Finland) region. Account and grant data is stored and processed in the EU; transfers outside the EU happen only in the narrow cases flagged in the sub-processor list below (e.g. transactional email).
Encryption in transit
All traffic to the website and the MCP endpoint is served over HTTPS/TLS (Let’s Encrypt certificate, auto-renewed). Connection-level encryption is enforced at the Caddy reverse proxy.
Backups & resilience
- Daily Hetzner Cloud Backup (7-day retention) plus application-level, WAL-safe snapshots taken before major changes.
- Continuous uptime monitoring with alerting on the /health endpoint.
Access & authentication
- Per-user bearer API keys; OAuth tokens with expiry, rotation and revocation (RFC 7009).
- Per-request rate limiting on both IP and token (Caddy zone).
- No third-party scripts, advertising cookies or tracking pixels on the public surface.
Data minimisation
The MCP server’s request log records metadata only (timestamp, token id, tool name, status code, latency) — never the content of your tool calls. Log rows auto-purge after roughly 90 days.
Sub-processors
A small set of carefully chosen providers helps us run the service:
- Hetzner Online (EU, Germany/Finland) — hosting and infrastructure
- Resend — transactional email (confirmations, password reset)
- UptimeRobot — uptime monitoring
- healthchecks.io — data-refresh run monitoring (receives no personal data)
The authoritative, up-to-date sub-processor list and data-processing terms are stated in our Privacy policy; the underlying Data Processing Agreements (DPAs) are still being finalised with counsel.
Responsible disclosure
If you find a security issue, please tell us at info@grantcortex.eu. Details are also published in our RFC 9116 security.txt (languages: en, hu).