Technical transparency

Trust, privacy and human control

See where customer data is hosted, which processing boundaries apply, and how deterministic rules, AI-supported proposals and human decisions remain distinguishable.

Review statusThis is a technical transparency draft based on the implemented architecture. It is not a certification, legal advice, a data processing agreement or an availability guarantee. Legal review is pending before contractual use.

Technical content version: 2026-07-28

Verified technical principles

These statements describe product and operating boundaries that are represented in the current architecture. They deliberately avoid legal conclusions and absolute guarantees.

Customer data hosted in Germany

The application database and customer file storage are configured for German hosting locations. Production and staging use separate data stores.

Boundary: Customer-authorized provider connections can transfer selected data to the connected third-party service.

Operational monitoring within the EU

Operational service-readiness signals are monitored from an independently operated system located within the European Union.

Boundary: Operational monitoring is kept separate from customer-facing audit records and is not intended to contain project content.

Separated environments

Production and staging use separate configuration, secrets, databases, storage identities and provider credentials.

Boundary: Separation reduces cross-environment exposure; it is not a statement that every possible operational risk is eliminated.

Purpose-bound data minimization

Provider and AI requests use task-specific allowlists, bounded payloads and customer-visible scopes instead of unrestricted integration project exports.

Boundary: Uploaded or connected source content can still contain personal or confidential information and must be governed by the customer.

Integration project-scoped access

Server-side membership and permission checks protect integration project data. Roles, critical permissions and relevant changes are auditable.

Boundary: The user interface is not an authorization boundary; every protected request is checked again by the backend.

Controlled provider connections

Microsoft and Atlassian connections are explicitly authorized, integration project-bound and limited to implemented discovery, search and linking workflows.

Boundary: The connected provider remains responsible for its own service and data processing. No connection is activated implicitly.

AI is opt-in and task-bound

AI is disabled by default. An integration project administrator must enable an approved provider mode, specific tasks, data categories and a finite budget.

Boundary: Redaction and minimization reduce exposure but do not guarantee complete anonymization of free-form content.

Human decision authority

AI-generated findings are presented as proposals or information with provenance. Governed automation is bounded, auditable and reversible where implemented.

Boundary: MyIntegrationHub does not claim that AI makes legally binding or autonomous professional decisions.

Service and provider categories

A category is used only when required by the corresponding product function or when an authorized customer activates a connection. Exact contractual roles and legal bases require legal review.

CategoryTechnical purposeActivation boundary
Application and database hostingRun the service and store structured customer data in Germany.Core service
Object storageStore uploaded customer files in a private German storage location.Used when customers upload files
Operational monitoringMonitor public service-readiness signals from within the EU.Operational metadata only
Transactional emailDeliver account, verification, invitation and security messages.Triggered by account workflows
Payment processingCreate checkout sessions and process subscription transactions.Only when a customer initiates billing
IONOS AI Model HubProcess bounded task context for explicitly enabled AI functions.Platform gate plus integration project opt-in
Microsoft Entra SSOAuthenticate users through a customer-authorized enterprise identity provider.Disabled by default; explicit platform and organization configuration
Microsoft and Atlassian connectionsDiscover, search and link customer-selected external sources.Explicit OAuth authorization and integration project assignment

How results are classified

Deterministic calculation

Documented rules calculate status, readiness, schedules and scenario impacts from visible structured inputs. They are not statistical predictions.

AI-supported proposal

Approved AI tasks receive bounded context and return schema-validated suggestions with evidence references, data gaps and safe failure states.

Human confirmation

A person with the required permission reviews, accepts, rejects or edits proposals before they become governed project records, except for explicitly enabled reversible draft automation.

Detailed information

The privacy and cookie pages describe the current processing surfaces in more detail. Contact us for technical due-diligence questions. Contractual documents remain subject to separate agreement and legal review.