Security
How OurAI protects your data, layer by layer.
Architecture
OurAI runs as three separate services. Each has its own database and its own credentials, and they talk to each other only over mutual TLS.
The data plane holds your conversations, your files and the audit log. It is the only service that talks to AI providers. It stores no name and no email address. There, you are a random identifier.
The control plane holds who you are and who belongs to your organisation: Names, email addresses, members, roles and sign-in.
The accountant holds your subscription, your seats and your usage ledger. Payment details, card or invoice, are held by Stripe and never stored by us. The accountant never sees a prompt.
Because the databases are separate, a break-in at one service does not expose what the others hold. The one deliberate exception is our internal analytics, which reads across them under column-level grants and is reachable only from our own IP addresses.
The platform runs in Hetzner's datacenter in Helsinki, Finland.
If you need OurAI on your own servers, contact us.
Defence in depth
Several independent layers protect your data, from the datacenter to your own account.
The platform runs in a datacenter operated by Hetzner, which is responsible for the physical security of the building and the hardware. Hetzner also filters DDoS attacks before they reach our server.
A firewall at Hetzner, outside the server itself, refuses every port except the three below. A service that opened a port by mistake would still not be reachable.
- 443: HTTPS, including HTTP/3
- 80: Redirect to HTTPS
- 8443: Licensing for self-hosted customers, requires a client certificate
All traffic to OurAI is encrypted with TLS 1.3, and older protocol versions are rejected. HSTS instructs browsers never to connect over plain HTTP. The three services call each other only over mutual TLS: Both sides authenticate with a certificate issued by our internal certificate authority, and each service accepts only the services on its allowlist.
Inside the database, the content of your conversations, your files and the audit log are encrypted with AES-256-GCM under a data key unique to your organisation. Each data key is itself encrypted with a master key held outside the database, so a copy of the database does not expose that content.
Separation between organisations is enforced by Postgres row-level security, not by application code. The database role our services connect as cannot bypass it, and a query without an organisation attached returns no rows.
Sign-in runs on Authentik, an open-source identity provider we host ourselves. Repeated failed attempts lower the reputation of the source address and username until further attempts are blocked. Two-factor authentication with TOTP or WebAuthn is available on every plan. Access tokens are short-lived JWTs that expire after 15 minutes and are verified on every request.
API keys belong to a single user and act with that user's current role. Each key is a 256-bit secret, shown once when it is created and stored only as a SHA-256 hash. A key can only send requests to AI models. Managing members, policies, billing or the audit log requires signing in. A revoked key stops working within 60 seconds.
Secure development
Our test suite includes negative security tests, which verify that unauthorised access is denied, not only that authorised access succeeds. Every merge request runs the suite in CI against a PostgreSQL instance provisioned with the same roles, grants and row-level security policies as production. Backend changes affecting authentication, tenant isolation, service-to-service authentication, billing or the gateway undergo an adversarial review by an internal AI penetration tester before release.
All dependencies are locked to exact versions and verified by cryptographic hash. Every third-party container image, including the base images our own images are built on, is pinned by SHA-256 digest, so every deployment is reproducible.
In September 2026, Aikido Security performed an independent penetration test of the platform. The test identified no critical or high-severity vulnerabilities, and all minor findings have since been closed following a retest.
Operations
The production server is reachable for administration only over a private network, with SSH key authentication, and privileged commands require a separate password. Application secrets are stored on the server with file permissions that restrict them to the service account the platform runs under.
Application logs and error reports never contain prompts or responses. They record request metadata such as timings, status codes and policy decisions. Credentials, tokens and API keys are redacted before a log entry is written or an error report is sent, and error reporting runs with personal-data collection disabled.
The production server is backed up daily by Hetzner, and the seven most recent backups are retained. Each backup is a full image of the server's disk, so every database is captured at the same point in time and a restore brings the services back consistent with each other.
Availability is monitored by an external service, independent of our own infrastructure, so an outage on our side cannot disable the monitoring. Background workers, including billing, retention and erasure, send regular heartbeats, and a missed heartbeat raises an alert. The current status of the platform is published at status.ourai.dk.
Report a vulnerability
If you find a vulnerability, email avl@ourai.dk. You receive an acknowledgement within two business days and a substantive response within ten.
We will not take legal action against good-faith research that avoids other users' data and does not disrupt the service. Please allow us 90 days to fix the issue before disclosing it.