Our Security

Security and transparency by design.

Picologic operates infrastructure predominantly in Germany and prefers European or German data center locations where this is practical for the service.

Where a service uses external cloud, API or AI providers, especially providers based in the United States, we disclose that context at the respective service boundary.

German infrastructure where possible. Transparent disclosure where not. Security as an ongoing engineering process.

Default infrastructure provider

Unless a service states otherwise, Picologic uses Hetzner Online GmbH for server infrastructure.

Hetzner operates an ISO/IEC 27001:2022 certified information security management system. The certified scope covers the hosting services and data centers of Hetzner Online GmbH.

This is Hetzner's certification as infrastructure provider. It is not presented as a Picologic company certification.

External and US services

Some customer solutions can require external cloud services, APIs, email delivery providers, payment providers or AI services.

When data touches a provider outside our default German infrastructure, this must be visible in the service documentation, contract context or implementation notes.

Additional providers and subprocessors can be listed per service instead of being hidden behind a generic platform statement.

Artificial Intelligence / OpenAI

For selected AI functionality, Picologic currently uses services from OpenAI.

For OpenAI business/API usage, inputs and outputs are not used to train OpenAI models by default unless a customer explicitly opts in to data sharing for that purpose.

Processing, retention and model training are separate topics. We therefore do not claim that data is never transmitted to OpenAI or never retained.

Operational controls

  • Role-based access and separation of duties where systems require it.
  • Traceable deployment and change workflows through Git and operational logs.
  • Monitoring for availability, failures and relevant infrastructure signals.
  • Data minimization and service-specific disclosure for external providers.
  • Human review for critical AI-supported actions and customer-facing changes.
  • No unsupported absolute guarantees about security outcomes.

Need service-specific details?

For customer projects we document the concrete infrastructure, providers, data flows and security-relevant operating assumptions for the respective implementation.