Security & Data Sovereignty with GAPTEQ
With GAPTEQ, you decide where your data is stored, who has access to it, and how your application uses the data. Security, compliance, and data sovereignty – all under your control, not ours.
What you should know about your data
Where is my data stored?
Your data is stored in your own database or lakehouse platform, not in a GAPTEQ silo.
Who can access it?
Only those whom you have authorized through your permissions policy have access.
How is my application protected?
Your app is secure: encrypted, protected against attacks, and continuously updated.
What does AI do with my data?
GAPTEQ AI processes only the data that you explicitly share. Nothing more.
Your data stays where it is
You decide where GAPTEQ runs
GAPTEQ can be fully integrated into your on-premises infrastructure or operated flexibly as a cloud-based solution. Decide which option works best for you.
Security that just runs in the background
Encrypted connection
HTTPS is enforced on the server side; unencrypted requests are not permitted under any circumstances.
Protection against common attacks
Protection against known attack patterns targeting web applications is built into GAPTEQ from the ground up.
Ongoing patch management
Security-related updates are released regularly, and customers are actively kept informed.
Tested in the field
Penetration tests have already been successfully conducted for customers.
Granular access control at every level
Permissions can be controlled at a granular level across multiple tiers: from application login, through individual pages, all the way down to the record level. This ensures that each user truly sees and edits only what they are authorized to access. Create internal users or import users and groups from directory services or Entra ID – managed centrally rather than maintained individually.
Control even with AI
GAPTEQ Assist is the gateway to established AI services such as OpenAI, Microsoft Azure OpenAI, DeepSeek, and Google Gemini – right within your application. The AI only has access to explicitly authorized data, not your entire dataset. This shifts the question from “Should we use AI at all?” to “Which specific data should we make available?”
Reliable for over 10 years
“GAPTEQ ensures the data security and transparency required for our tax analyses, which we found difficult to achieve using Excel spreadsheets.”
Economics Department, Augustinum Nonprofit LLC
“GAPTEQ is as unique as our app. As a GDPR-compliant low-code platform for SQL databases, it has no equivalent on the market.”
Dr. Tina Mandel, Founder, dentinostic
Frequently asked questions about security and data protection at GAPTEQ
Your data is stored in your own SQL database or Lakehouse platform. GAPTEQ does not have a built-in data store, so it does not create any (new) data silos. Your data remains where you already manage and secure it today.
Yes, GAPTEQ provides the necessary tools to create applications that are fully GDPR-compliant.
Protection against known attack patterns is built into the software from the ground up, supplemented by regular security updates and penetration tests that have already been successfully conducted for customers.
GAPTEQ Assist only has access to the data that you explicitly authorize it to access. It does not have blanket access to your entire dataset.
Yes, GAPTEQ includes a built-in permissions system by default. You can individually control who is allowed to view or edit which data. Permissions are granted at various granular levels – from application login to individual pages and down to the record level. Users can log in via internal accounts, directory services, or EntraID.
Do you have questions about security or your specific use case?
To ensure nothing is left unclear: Talk to us about your specific requirements for security, data storage, and access.