Security & trust
Your plans are confidential. We build like it.
Project data is some of the most sensitive data a company has — it says what you're building, with whom, and when. Here is exactly how Pragma handles it.
EU-only hosting
Application, database and file storage run in AWS eu-west-1 (Ireland) — Couchbase Capella in the same region. Analytics (PostHog) and email (Resend) run in their EU regions.
Encryption everywhere
TLS in transit for every connection. Encrypted at rest: managed encrypted database volumes, server-side encrypted file storage, and per-organization KMS keys for integration secrets.
Authentication done right
Identity by Ory. Two-factor authentication available to every plan. Single sign-on (SAML/OIDC) on Enterprise. AI apps connect through OAuth 2.1 — no long-lived API keys in config files.
Permissions to the item
Access scopes by project, area, item type — down to a single item — for people, teams and connected apps. Permissions are enforced in the database layer, and inherited sensibly down project trees.
A history you can audit
An append-only, organization-wide activity history records every change — including which connected AI app made it — filterable and exportable (CSV/JSON). Retention from 7 days to unlimited by plan.
Backups and exit
30-day rolling encrypted backups. Self-service JSON export of your whole organization at any time, plus a 30-day export window after cancellation. Your data is yours, including on the way out.
GDPR-native
Built in France under the GDPR from day one: self-service personal-data export, hard deletion (no soft-delete of accounts), EU processors by default and standard contractual clauses where a US processor is unavoidable.
AI with boundaries
AI features run only on the content you point them at, never train models, and can run on your own API key — including a model server on your own network that Pragma’s cloud never touches.
Where we are honest about maturity
Pragma is a young product from a small French company, and we'd rather tell you plainly: we do not yet hold a SOC 2 or ISO 27001 certification — formal certification is on our roadmap as the company grows. We operate with an internal availability target of 99.5%, announced maintenance windows outside CET business hours, and a formal SLA on Enterprise agreements. Security disclosures and questions: contact@dappit.fr — security testing requires prior written authorization.
Questions before you commit data?
Write to us — you'll get an engineer, not a ticket queue.
contact@dappit.fr