Skip to content
pragma

Security & trust

Your plans are confidential. We build like it.

Project data is some of the most sensitive data a company has — it says what you're building, with whom, and when. Here is exactly how Pragma handles it.

EU-only hosting

Application, database and file storage run in AWS eu-west-1 (Ireland) — Couchbase Capella in the same region. Analytics (PostHog) and email (Resend) run in their EU regions.

Encryption everywhere

TLS in transit for every connection. Encrypted at rest: managed encrypted database volumes, server-side encrypted file storage, and per-organization KMS keys for integration secrets.

Authentication done right

Identity by Ory. Two-factor authentication available to every plan. Single sign-on (SAML/OIDC) on Enterprise. AI apps connect through OAuth 2.1 — no long-lived API keys in config files.

Permissions to the item

Access scopes by project, area, item type — down to a single item — for people, teams and connected apps. Permissions are enforced in the database layer, and inherited sensibly down project trees.

A history you can audit

An append-only, organization-wide activity history records every change — including which connected AI app made it — filterable and exportable (CSV/JSON). Retention from 7 days to unlimited by plan.

Backups and exit

30-day rolling encrypted backups. Self-service JSON export of your whole organization at any time, plus a 30-day export window after cancellation. Your data is yours, including on the way out.

GDPR-native

Built in France under the GDPR from day one: self-service personal-data export, hard deletion (no soft-delete of accounts), EU processors by default and standard contractual clauses where a US processor is unavoidable.

AI with boundaries

AI features run only on the content you point them at, never train models, and can run on your own API key — including a model server on your own network that Pragma’s cloud never touches.

Where we are honest about maturity

Pragma is a young product from a small French company, and we'd rather tell you plainly: we do not yet hold a SOC 2 or ISO 27001 certification — formal certification is on our roadmap as the company grows. We operate with an internal availability target of 99.5%, announced maintenance windows outside CET business hours, and a formal SLA on Enterprise agreements. Security disclosures and questions: contact@dappit.fr — security testing requires prior written authorization.

Questions before you commit data?

Write to us — you'll get an engineer, not a ticket queue.

contact@dappit.fr