Evrondesk
Trust center

Your data, handled with care

This page is maintained by the Evrondesk team to answer common security, privacy and compliance questions about the product. It describes controls we have enabled today. It is not an independent certification.

Access & authentication

Email/password and Google sign-in. Multi-factor authentication is enforced on all super-admin actions and available to every user. Sessions can be reviewed and revoked from account settings.

Platform & hosting

Evrondesk runs on Cloudflare Workers at the edge. Data is stored in a managed Postgres database with encryption at rest; connections use TLS 1.2+.

Audit & retention

Reads, writes and deletes on contacts, deals, notes, tickets, meetings and attachments are captured in an immutable access log retained for 6 years. Data export and deletion available on request.

Incident & security contact

For vulnerability reports or security questions, email security@evrondesk.com — we respond within one business day.

Subprocessors

Third-party services Evrondesk uses to operate. We notify customers of material changes to this list.

SubprocessorPurposeRegion
Cloudflare, Inc.Edge hosting, DNS, DDoS protectionGlobal (EU/US)
Supabase Inc.Managed Postgres database, authentication, storageEU (Frankfurt)
ResendTransactional email deliveryUS / EU
Stripe, Inc.Payment processing for paid plansUS / EU
OpenAI / Anthropic / Google AIAI features (opt-in per workspace)US

Shared responsibility: Evrondesk maintains the platform. You configure who can access your workspace, what data you upload, and your own retention preferences.