Security & Compliance

Enterprise-grade protection for your portfolio company data, built on German infrastructure standards.

ISO 27001 Certified
EU Data Only
Tenant Isolation

Hetzner Certifications

Your data is hosted exclusively in EU data centers operated by Hetzner, a German cloud provider with enterprise-grade security certifications.

ISO/IEC 27001:2022

SOCOTEC

Information Security Management System certified across all data centers

BSI C5 Type 2

German Federal BSI

Cloud security controls verified over time by Federal Office for Information Security

§8a BSIG (KRITIS)

BSI

Classified as critical infrastructure operator under German law

GDPR Compliant

EU

Data processing within EU jurisdiction, no third-country transfers

Technical and Organizational Measures (TOMs) are independently audited by TÜV Rheinland.
Data center locations: Nuremberg, Falkenstein (Germany), Helsinki (Finland)

Built-In Security Controls

Security is embedded at every layer of the ValueGen platform, from network to database.

Layer Protection
Encryption in Transit TLS 1.3 via Let's Encrypt with auto-renewed certificates
Authentication JWT tokens in httpOnly cookies with secure + sameSite flags
MFA Support Optional two-factor authentication for admin accounts
Tenant Isolation PostgreSQL Row-Level Security (RLS) — each PE firm's data is cryptographically isolated at the database level
Network Isolation Internal Docker networks; only reverse proxy exposed publicly
Password Storage Bcrypt hashing with salt — never stored in plain text

Server Hardening

Defense-in-depth approach with multiple security layers at the operating system level.

Measure Implementation
Firewall UFW configured with only ports 80/443 exposed
Intrusion Prevention fail2ban actively blocks brute-force login attempts
OS Security Ubuntu 22.04 LTS with automatic unattended security updates
Access Control SSH key authentication only — password auth disabled

Why This Matters

Security designed specifically for the regulatory and confidentiality requirements of private equity.

EU Data Sovereignty

Your portfolio company data never leaves EU jurisdiction. German-owned infrastructure means no exposure to US Cloud Act or foreign data access requests.

Regulatory Alignment

ISO 27001 + BSI C5 certifications satisfy due diligence requirements for most LPs and regulatory bodies. Documentation available on request.

Full Audit Trail

Complete activity logging tracks all user actions, document access, and data changes. Export audit reports for compliance reviews.

Complete Tenant Isolation

Each PE firm's data is separated at the database level with Row-Level Security. No risk of cross-tenant data leakage.

Your data is protected by German engineering standards: ISO 27001-certified infrastructure, database-level tenant isolation, and encryption at every layer — all within EU borders.

Ready to Secure Your Portfolio Data?

Schedule a demo to see how ValueGen protects your sensitive portfolio company information.