Data security and sovereignty

Your data stays where it belongs.

bundes.app is built from the ground up for public administration: processing runs on self-hosted servers in Germany or on models hosted within the European Union. No data transfer to US providers, no external clouds.

Government forms contain particularly sensitive personal data. That is why bundes.app treats digital sovereignty not as an add-on, but as the foundation of its entire architecture.

Self-hosting in Germany

The application and the AI models run on your own or a dedicated infrastructure in Germany. You retain full control over where documents are stored and processed.

EU-based or local open-source models

Extraction uses open-source language models, run locally or with EU providers. Because the interface is vendor-neutral, you avoid lock-in to any single manufacturer.

No data transfer to the US

Document contents are never transmitted to providers outside the EU. There is no connection to US clouds and no transfer to third countries.

GDPR from the start

Access is limited to authenticated staff. Every security-relevant action is logged, and documents can be deleted completely and irreversibly at any time.

Local address matching

Address plausibility checks run against an official directory held locally. No addresses are sent to external services such as postal or mapping providers; the matching never leaves the server.

Sovereignty is not an extra, it is a prerequisite.

Cookieless, anonymous analytics, no external fonts or content networks, encrypted transmission over TLS. Processing stays auditable and entirely in your hands.