Regingada
Regingada UG (haftungsbeschränkt)

Regingada Trust Center

We hold no SOC 2 and no ISO certificate. This page shows what we actually do — and what we deliberately don't.

Last updated: 2026-07-01

See our posture
T2 · Posture

Posture at a glance

Data residencyEU production residency is the target (Frankfurt) — a goal, not yet live. The core tool runs in your browser either way.
HostingVercel (Vercel Inc., USA) — static hosting/CDN for this site and the product files, deployed from GitHub. Listed in the subprocessor table below.
AI processingOpt-in only. Requests go through a Cloudflare Worker proxy to Anthropic (Claude). No AI request leaves the browser without your explicit action.
Accounts requiredNone. The suite has no login.
Tracking / adsNone. No analytics vendor, no ad network, no CRM pixel — on the product and on this site.
Core data modelLocal-first: profile and settings live in your browser (LocalStorage). The core tool has no server-side persistence.

Data we touch — and data we don't

  • Funnel inputs — transient, purpose-bound, only when you submit them
  • Functional browser storage only (LocalStorage: language, theme, profile)
  • Payment data — never collected
  • Health data — never collected
  • Tracking cookies — none
  • Profiling / behavioral scoring — none

What exactly sits in your browser

LanguageYour UI language (EN/DE). Never leaves the browser.
ThemeLight/dark preference. Never leaves the browser.
ProfileYour self-assessment profile. Leaves the browser only as part of a submission you actively trigger.
DeletingOne click in the suite's settings — or your browser's site-data controls. No request to us needed; we could not delete it for you even if asked, because we never hold it.

By default the Regingada Compliance Suite frontend loads zero external resources — open your own DevTools network tab and verify it. Network paths open only on your action: the opt-in AI request, a deliberate funnel submission, and — if you use them — the contact form (Zoho Forms, EU) or the EU-representation inquiry form (Formspree, USA, on consent).

How data flows — the whole picture

Your browser — the default boundary

The Regingada Compliance Suite runs entirely here. LocalStorage holds language, theme and profile. Zero external loads at boot.

↓ data crosses this line only on your action ↓

Path A · opt-in AI question

Browser → Cloudflare Worker → Anthropic (Claude)

Only what you type, only after consent. Not stored by us.

Path B · deliberate funnel submission

Browser → artifact service → DRAFT artifact

Transient processing; the artifact expires automatically — deleted after 14 days at the latest (current default).

Path C · contact form (optional)

Browser → Zoho Forms (EU) → office@regingada.com

Only if you use the contact form. EU-hosted, delivered internally Zoho→Zoho — no third-country transfer.

Path D · EU-representation inquiry (optional)

Browser → Formspree (USA) → Regingada UG (haftungsbeschränkt)

Only if you submit the representation form and tick consent. Third-country transfer on Art. 49(1)(a) GDPR consent; details requesting legal advice are shared with the law firm Theo Funk for a separate mandate.

Data residency — where your data actually sits today

A plain map of where processing happens, role by role — no more than our infrastructure actually supports today.

  • The core Regingada Compliance Suite runs in your browser: profile and settings stay in LocalStorage, with no server-side persistence.
  • Mandate material (§ 203 StGB) is not processed in the USA — the law firm's §203 tooling runs locally on the lawyer's own machine (localhost-only, no external hops).
  • Where a server-side database is used for back-office operations, it runs in an EU region (Supabase on AWS).
  • This website and the static product files are served by Vercel Inc. — a USA-based vendor on a global edge network — listed in the subprocessor table above.
  • The only path that reaches a US AI provider is the assistant (Anthropic) — and it is access-gated: without a released access code the proxy answers 403 and no query leaves the browser. For code holders it runs on explicit action only, under Zero-Data-Retention and the EU Standard Contractual Clauses.
  • Forms are split: the contact form is EU-hosted (Zoho, Netherlands); the EU-representation inquiry and the three transactional forms — access request on the integrations page, playbook delivery, exposure estimate — are delivered by Formspree (USA) only on your Art. 49(1)(a) GDPR consent. On cn.regingada.com those submissions additionally pass through our own server in Hong Kong (nginx /form-relay), which forwards them without storing them.

A dedicated EU production residency for all server-side features is a stated roadmap target — not yet live. See “What we don’t have (yet)”.

Where data goes, path by path

Path Destination / provider Legal basis or condition What does not happen
Suite twin data (profile, settings) Your browser only — LocalStorage No transmission: the data never leaves the device No server-side copy, no account, no sync across devices
Website delivery (EN/DE) Vercel Inc., USA — global edge network Necessary to deliver the pages you request; listed in the subprocessor table below No funnel documents and no AI content run through this path
Delivery of the Chinese edition Our own server in Hong Kong; the hosting provider is bound as a processor Necessary to keep cn.regingada.com reachable in that market No third-party CDN sits in this path
AI assistant (EN/DE) — access-gated, opt-in Cloudflare Worker proxy → Anthropic PBC, USA Access code required (no code = 403, no transmission); then on your explicit action only; EU Standard Contractual Clauses (Art. 46(2)(c) GDPR), Zero-Data-Retention active No request without your action; the prompt is not stored by us
AI assistant (Chinese edition) — access-gated, opt-in Same-origin relay on our Hong Kong server → DeepSeek, People's Republic of China Access code required (the relay rejects queries without a minted token); then on your explicit action only; the Chinese edition uses a provider reachable in that market Map, cockpits and search work entirely without AI
Contact form (kontakt.html) Zoho Corporation B.V., EU (Netherlands) → office@regingada.com Handling the enquiry you send; delivered internally Zoho→Zoho No third-country transfer on this path
Transactional forms and the EU-representation inquiry Formspree, Inc., USA — on cn.regingada.com additionally via our Hong Kong relay, which stores nothing Your consent under Art. 49(1)(a) GDPR, ticked in each form; without the tick nothing is sent No mailing list and no advertising use; EU alternative: contact form or plain email
Back-office database Supabase, EU region Operating the server-side back office No suite twin data and no mandate material are held here
Mandate material (§ 203 StGB) Locally on the lawyer's own machine Professional secrecy under § 203 StGB, BORA and BRAO from the moment the mandate starts No external hop, no US processing, no server coupling between product and firm

This table describes what the infrastructure actually does today — not what is planned.

T2b · Measures

Technical and organisational measures

What we can actually point to: properties of the architecture and of the deployment, not a certificate. The detailed TOM document is available on request — see Documents below.

self-assessed · verifiable in code

Architecture and access

  • Client-only core: the suite's twin data — profile and settings — stays in your browser. There is no server-side persistence and no account, so no central store of it exists anywhere.
  • Transport encryption: every path that leaves the browser runs over HTTPS/TLS — the sites as well as the form and AI endpoints.
  • Access separation: Regingada UG (software and appointed EU representation) and the law firm Theo Funk (legal advice under a separate mandate) work on separate systems; the handover is a deliberate act, not an automatic server coupling.
  • Roles and permissions in the server-side parts: authentication fails closed (an empty or missing token yields HTTP 503), the lawyer-only endpoint carries its own bearer token, and CORS origins are an explicit allowlist set by environment configuration.

Retention, deletion and backups

  • Transactional form requests (access request, playbook delivery, exposure estimate) are deleted once the request has been handled, at the latest six months after receipt, unless statutory retention duties apply — the same period as in the privacy policy.
  • Generated artifacts expire automatically — after 14 days at the latest (current default) — and an automated sweep deletes the expired files.
  • Browser data is deleted by you: one click in the suite's settings, or your browser's site-data controls. We hold no copy we could delete on your behalf.
  • Backups: site content and configuration are versioned in Git and every published state is redeployed from that source; the back-office database uses the managed backup function of its EU-hosted platform.

Operations

  • Logging: server-side logs are limited to what operating the service requires; the Chinese edition's AI and form endpoints additionally carry a per-IP rate limit. No analytics product, no ad network and no tracking pixel is deployed on any page.
  • Updates and patches: every change is redeployed from source, and server packages are updated with the deployment. Fonts, icons and data ship inside the application, so no third-party CDN can change under us.
  • Key handling: provider API keys and server tokens live only in server-side environment configuration — never in the repository, never in client-side code.
  • AI and training data: we train no models ourselves and keep no dataset of user inputs. For the opt-in assistant, Zero-Data-Retention is active with the AI provider used (confirmed 2026-06-17, see the subprocessor section below).

This is a self-assessed description of the system, not a certificate and not an audit opinion. Questions and corrections are welcome — the security contact is at the bottom of this page.

T3 · Two products, one boundary

The software ↔ mandate boundary, explained

Software output is a DRAFT and is not legal advice. FINAL exists only after you engage the law firm Theo Funk under a separate mandate and a lawyer has reviewed the matter. This is not small print — it is the architecture.

Product 1 · public

Regingada Compliance Suite — Regingada UG (haftungsbeschränkt)

  • Regime: GDPR + RDG (structured self-assessment, decision support)
  • No mandate, no legal advice, no professional-secrecy claim
  • Output: DRAFT artifacts, visibly labeled
Mandate · on engagement

Law firm Theo Funk

  • Regime: § 203 StGB + BORA/BRAO professional secrecy
  • Protected by professional secrecy once you become a client
  • Output: FINAL artifacts after lawyer review

Why the boundary protects you

  • No pseudo-advice: the software never pretends to be your lawyer.
  • A clear liability address in every phase — software company or law firm, never a blur.
  • The mandate handoff is a deliberate, documented act — no silent server coupling between product and firm.
T4 · Controls

Controls — self-assessed, verifiable in code

We run no continuous-monitoring product, so you will find no green “Passing” theater here. Each control is stated as a fact, labeled as what it is, and reviewed manually. Frontend controls you can verify yourself (DevTools); for server-side controls we share the relevant code excerpts on request by email.

Last reviewed: 2026-06-12 · status label for every control: self-assessed · verifiable in code

Data minimization

  • The suite requires no account; no user database exists for the public product.
  • No third-party trackers, analytics or advertising scripts are embedded.
  • Funnel inputs are processed for the stated purpose only and are not reused.

Transport & access

  • API authentication fails closed: an empty or missing server token yields HTTP 503 — never an open endpoint.
  • The lawyer-only endpoint (DRAFT→FINAL flip) is bearer-token-protected and rejects empty credentials.
  • CORS origins are an explicit allowlist set via environment configuration; credentials are not shared cross-origin.

Artifact security

  • Download identifiers carry 128 bits of randomness; enumeration is computationally infeasible.
  • Malformed identifiers are rejected before any file access (404 before filesystem).
  • Identifier format checks and deletion allowlists are kept in lockstep, so expired artifacts are always swept.
View 2 more categories

Retention

  • Generated artifacts expire automatically — after 14 days at the latest (current default) — and an automated sweep deletes expired files.
  • AI conversations are not stored by us; profile data stays in your browser until you delete it.

Frontend isolation

  • The Regingada Compliance Suite frontend performs zero external loads at boot and is offline-capable; network traffic occurs only for opt-in AI requests and deliberate funnel submissions.
  • Fonts, icons and data ship inside the application — no CDN dependency.
T5 · Subprocessors & AI chain

The entire list

Vendor Purpose · what flows Region
Vercel Inc. Static hosting/CDN — serves this site and the static product files, deployed from GitHub. No funnel documents or AI data pass through it. USA-based vendor (global edge)
Cloudflare Worker proxy for AI requests — carries opt-in AI prompts only, no funnel documents. Global edge (USA-based vendor) — SCC/DPA
Anthropic PBC Claude — answers for the opt-in AI assistant only. Nothing flows without your explicit consent and action. USA
Zoho Corporation B.V. Contact form (Zoho Forms) and company email (Zoho Mail). Contact-form submissions are delivered internally Zoho→Zoho to office@regingada.com. EU (Netherlands) — no third-country transfer
Formspree, Inc. Technical delivery of EU-representation inquiries to Regingada UG (haftungsbeschränkt) — only when you submit the form and tick the consent box. USA — transfer on Art. 49(1)(a) GDPR consent

That is the entire list. No analytics vendor, no ad network, no CRM pixel.

AI-provider safeguards: Zero-Data-Retention is active for the Anthropic account used (confirmed 2026-06-17). Anthropic's data-processing agreement (AVV/DPA) including the EU Standard Contractual Clauses is in force via Anthropic's commercial terms, so the opt-in AI transfer to the USA is covered by the SCCs (Art. 46(2)(c) GDPR). AI features remain strictly opt-in and clearly labeled.

T6 · Documents

View, or request by email

No portal, no NDA modal, no access tiers. Public documents open directly; sensitive ones are a short email away — answered by the lawyer, not a ticket queue.

Privacy policy (Datenschutzerklärung) As of: June 2026 View
Terms of use (AGB) As of: June 2026 View
Impressum (provider identification) As of: June 2026 View
Data-processing agreement (AVV/DPA) template In preparation Request by email
Detailed technical & organizational measures (TOMs) On request Request by email
T7 · FAQ

The questions procurement actually asks

Is the Regingada Compliance Suite legal advice?
No. The Regingada Compliance Suite is structured self-assessment and decision support under the German Legal Services Act (RDG) — not legal advice. Legal advice is provided exclusively by the law firm Theo Funk under a separate engagement. See the boundary section above.
What happens to my funnel inputs?
They stay in your browser until you actively submit them. After submission they are processed for the stated purpose only; generated artifacts expire automatically — after 14 days at the latest (current default) — and are swept by an automated deletion job.
What does the AI see, and when?
Only what you type into the opt-in AI assistant, only after you consent, and only for that request. The request travels through a Cloudflare Worker proxy to Anthropic (Claude). The map, cockpits and search work entirely without AI.
Where is data stored?
Profile and settings: in your browser (LocalStorage). The core tool has no server-side persistence. Server-side features (artifact generation) hold data transiently with automatic expiry. Messages you send via the contact form reach our Zoho Mail inbox (Zoho Forms, EU); an EU-representation inquiry you submit reaches Regingada UG (haftungsbeschränkt) via Formspree (USA, on your consent); details requesting legal advice are shared with the law firm for a separate mandate — both are in the subprocessor table. EU production residency remains a stated roadmap target.
How long is anything retained?
Browser data: until you delete it (one click in settings). Generated artifacts: 14 days at the latest (current default), enforced by a deletion sweep. AI conversations: not stored by us. If the default retention ever changes, it will be posted in the Updates feed.
Who is the controller?
For tool-usage data: Regingada UG (haftungsbeschränkt). Once you engage the firm, mandate data is handled by the law firm Theo Funk under professional-secrecy rules (§ 203 StGB, BORA/BRAO). The two roles never blur.
How does the mandate handoff work?
You decide to engage the firm — a deliberate, documented act. There is no silent server coupling between the public product and the firm's systems. Identity data carries over; everything mandate-relevant is collected fresh under the mandate's own rules.
Why no SOC 2?
The direct answer: we are a single-product company, and a SOC 2 audit currently buys less risk reduction than the architecture itself — no accounts, no tracking, local-first data, fail-closed auth. Certification stays under evaluation; if that changes, it will appear in the Updates feed first.
What happens if there is a security incident?
We contain and assess the incident first. Where the GDPR requires it, we notify the supervisory authority without undue delay — where feasible within 72 hours (Art. 33 GDPR) — and affected persons without undue delay (Art. 34 GDPR). Every security-relevant incident also becomes a dated entry in the Updates feed on this page. The architecture keeps the blast radius small: no accounts, no central user database, artifacts expire automatically.
How do I report a vulnerability?
Email the lawyer directly — see Contact & Responsible Disclosure below. Good-faith research is welcome; we commit to acknowledging reports and will not pursue good-faith reporters.
T8 · Updates

Security changelog — real entries, real dates

Cadence over volume: few entries, each one true. Completed roadmap items from “What we don't have (yet)” land here with a date.

Transparency§

Trust Center brought up to date with the live state

Hosting (Vercel), the subprocessor list (added Zoho Forms/EU and Formspree/USA), the AI-provider status (zero-data-retention active) and the data-flow diagram were updated to match the live deployment and the privacy policy.

Transparency§

Contact channels added: contact form + RaaS inquiry

A contact form (Zoho Forms, EU-hosted, delivered to office@regingada.com) and the RaaS wizard's inquiry form (delivered to the law firm Theo Funk via Formspree, USA, on explicit consent) went live. Both are now listed as subprocessors.

Transparency§

Public launch on Vercel

regingada.com went live, served statically by Vercel with GitHub auto-deploy. Vercel is now listed in the subprocessor table.

Privacy§

AI provider Zero-Data-Retention activated

Anthropic confirmed zero-data-retention for the account used by the opt-in AI assistant. The data-processing agreement (AVV/DPA) including the EU Standard Contractual Clauses applies via Anthropic's commercial terms, so the USA transfer is covered by Art. 46(2)(c) GDPR.

Transparency§

Trust Center published

First publication of this page. Posture, controls and subprocessor list self-assessed as of this date.

Security§

Download identifiers hardened to 128-bit entropy

Artifact download IDs moved from 32 to 128 bits of randomness; malformed identifiers are now rejected before any file access; the retention deletion allowlist was updated in lockstep.

Security§

API auth fail-closed; CORS allowlist via environment

A deployment path that could leave the lawyer endpoint with an empty token was closed: empty token now returns 503 (fail-closed). CORS origins moved to an explicit environment allowlist.

Want update notices? One email, no newsletter tool, no new data flow: request updates by email.

T9 · The honest gap list

What we don't have (yet)

Absence stated openly, with a dated status. Every finished item moves to the Updates feed with a date.

Not yet Status as of 2026-07-01

Certifications (SOC 2 / ISO 27001)

Under evaluation — a sober cost/benefit question for a single-product firm whose architecture minimizes data in the first place.

Not yet Status as of 2026-07-01

EU production residency

Target: Frankfurt region for all server-side features. Tracked as a roadmap milestone; completion lands in the Updates feed.

Not yet Status as of 2026-07-01

External penetration test

Planned. The executive summary will be published on this page — findings status included.

T10 · Contact & Responsible Disclosure

Talk to a person, not a portal

ResponsibleTheo Funk, Rechtsanwalt (Rechtsanwaltskammer Bamberg)
Security contactoffice@regingada.com
What to reportVulnerabilities in the Regingada Compliance Suite, this website, the public API or the embed widget — with steps to reproduce if possible.
What we commit toAcknowledgment of your report, a serious look at every good-faith submission, and no legal action against good-faith security research.
Machine-readable contactsecurity.txt (RFC 9116) at /.well-known/security.txt — the same contact, machine-readable.