Security, stated plainly
A vault for your paperwork has to earn trust with specifics, not adjectives. This page lists what protects your documents in paless, in plain language, and what independent verification is on the way. If anything here is unclear, ask us at info@paless.eu.
The facts
Encryption
AES-256 at rest and TLS 1.3 in transit. Passwordless login with YubiKey and passkey support, so there is no password to phish.
Infrastructure
Dedicated, hardened European infrastructure with no Big Tech, and every document stored redundantly across separate European data centers.
Jurisdiction
Hosted, processed, and stored exclusively under European law. No transfer to the US, no access under the US CLOUD Act.
Sovereign AI
Pal runs entirely within the European Union. Your documents are never sent to OpenAI, Google, Microsoft (Azure), or any other Big Tech company.
Independent verification
Grey-box penetration testing, chaos engineering, a GDPR legal review, and an IDW PS 880 audit are being commissioned.
Exit path
No lock-in. Download a complete, structured export whenever you want, compatible with the open source paperless-ngx project.
Found a vulnerability?
We want to hear about it. Write to info@paless.eu and we will respond as quickly as we can. A machine-readable security.txt carries the same contact.
Common questions
How are my documents encrypted?
With AES-256 at rest and TLS 1.3 in transit. Login is passwordless, with YubiKey and passkey support.
Where do my documents physically live?
Exclusively on dedicated, hardened European infrastructure without Big Tech, stored redundantly across separate European data centers. No transfer to the US, no access under the US CLOUD Act.
Does the AI change the security picture?
No. Pal, the EU sovereign AI, runs entirely within the European Union, and your documents are never sent to OpenAI, Google, Microsoft (Azure), or any other Big Tech company.
Is any of this independently verified?
Independent verification is part of the plan, not an afterthought. Grey-box penetration testing, chaos engineering, a GDPR legal review, and an IDW PS 880 audit are being commissioned.
How do I report a security issue?
Write to info@paless.eu. A machine-readable security.txt with the same contact lives at paless.eu/.well-known/security.txt.