This page is maintained by the Evrondesk team to answer common security, privacy and compliance questions about the product. It describes controls we have enabled today. It is not an independent certification.
Email/password and Google sign-in. Multi-factor authentication is enforced on all super-admin actions and available to every user. Sessions can be reviewed and revoked from account settings.
Evrondesk runs on Cloudflare Workers at the edge. Data is stored in a managed Postgres database with encryption at rest; connections use TLS 1.2+.
Reads, writes and deletes on contacts, deals, notes, tickets, meetings and attachments are captured in an immutable access log retained for 6 years. Data export and deletion available on request.
For vulnerability reports or security questions, email security@evrondesk.com — we respond within one business day.
Third-party services Evrondesk uses to operate. We notify customers of material changes to this list.
| Subprocessor | Purpose | Region |
|---|---|---|
| Cloudflare, Inc. | Edge hosting, DNS, DDoS protection | Global (EU/US) |
| Supabase Inc. | Managed Postgres database, authentication, storage | EU (Frankfurt) |
| Resend | Transactional email delivery | US / EU |
| Stripe, Inc. | Payment processing for paid plans | US / EU |
| OpenAI / Anthropic / Google AI | AI features (opt-in per workspace) | US |
Shared responsibility: Evrondesk maintains the platform. You configure who can access your workspace, what data you upload, and your own retention preferences.