Patient data is Article 9 data. We treat it that way.
You carry the liability, not us. So this page says where the data sits and who else sees it — rather than that security is “important to us”.
MitaBase runs on its own servers at Hetzner in Nuremberg; patient data sits on a LUKS2-encrypted volume. Backups run nightly at 03:00, encrypted, to a second data centre. No third party is involved in the position path — our own map tiles, no Google, no Mapbox, no analytics.
Where the data sits
Hetzner, Nuremberg
LUKS2Patient data on a LUKS2-encrypted volume. Article 9 data never sits on an unencrypted disk.
Backups to a second data centre
restic · 03:00Encrypted with restic, nightly at 03:00, to Falkenstein. A fire in the primary loses no data.
SSH-key access only
22 · 80 · 443Root login and password login are closed. Ports 22, 80 and 443 are open — nothing else.
Who else sees it
In the position path: nobody
0 third partiesOur own map tiles and `geo:` links from the office. No Google, no Mapbox, no CARTO. A test pins it.
Push with no vendor
APNs · FCMThe server signs APNs and FCM itself. A device token never leaves it.
Routing is ours too
Self-hostedMap, route calculation and address search run on our own servers in Germany — no map service, no third-party key. A test pins it: no request leaves mitabase.com.
No analytics
0 trackersAnywhere. Not on this page either — check your browser's network tab.
Who may do what
Permissions in the server, not the interface
132 + 72132 routes behind the admin guard, 72 behind the driver guard. The build fails if any route uses the weak guard.
Logs nobody trims
no gapsWorking time and money are logged without gaps. Every deletion is master-only and needs a written reason, which lands in the log.
A password change ends every session
immediateImmediately, by token version — not at the next expiry.
Files are checked by their bytes
magic bytesAfter writing, not by filename. A renamed .txt is deleted and refused. Private documents live outside the web root and are never a link with a token.
What we do not have
This list is here because somebody would otherwise find it. We do not claim a certificate we do not hold — and a supplier who names their gaps is the only one whose other statements you can check rather than believe.
- No ISO 27001, no TISAX, no C5. No certification of any kind.
- No finished data processing agreement and no TOM document. Both come when they are written — we do not offer them before that.
- EXIF data in photos is not stripped. We would rather say so than imply a scrub that does not happen.
- No payer interface: no § 301, no § 302, no EDIFACT.
FAQ
Where exactly is the patient data?
On servers at Hetzner in Nuremberg, on a LUKS2-encrypted volume. Backups run nightly at 03:00, encrypted with restic, to a second data centre in Falkenstein.
Do we get a data processing agreement under Art. 28 GDPR?
Not yet. A finished agreement does not exist here today, so we do not offer one. As soon as it is written and reviewed it will be downloadable from this page.
Is MitaBase certified?
No. No ISO 27001, no TISAX, no C5. We name the technical measures you can verify yourself instead — down to this page's own network requests.
GPS in the vehicle — what about the works council?
They have a say, and rightly: this is co-determination under § 87 BetrVG. What is recorded is position during duty, working time and completed rides. No microphone, no private journeys, no evaluation after hours. Position sharing can be switched off; everything else keeps working.