Security and compliance
No cloud service. That is the product's most important property.
Webichive runs inside your network, on your servers, under your administration. We have no access to your captures and want none.
This page is written for the people who have to approve the installation: IT management, data protection officers, information security. Where a claim can be evidenced, the evidence sits next to it.
2outbound connectionsTarget site and timestamp authority, both logged
0TelemetryNo error reporting, no third party fonts
1ProcessorThe operator of our data centre in Vienna
4FindingsPenetration test 2025-11-24, all closed
What leaves your network and what does not
Two outbound connections, both necessary, both logged. Archived content is in neither of them.
Your network
Webichive applicationcontainer 8 vCPU 16 GB RAM
Crawl workersisolated per order no write access
Archive storages3://evidence object-lock retain 10y
Directory serviceldaps oidc 4 roles
Outside
Target websitehttps read only user agent documented
Timestamp authoritythe Merkle root only, 32 bytes
No telemetry service, no error reporting service, no third party fonts, no call home. Licence checking runs offline from a file.
01
02VERIFICATIONa3f9c1d2 e4b70855 c61f0da9 773be248 1c0596e7 f0a4bb2d 3e8c9517 0fbe4a622026-03-11T09:41:07Z
Requirements and how they are met
Nine points that tenders and approval reviews ask about again and again.
RequirementImplementationEvidence
Self-hostedOperations
A complete installation in your environment. There is no tenancy model, because there is no multi tenant service.
installation guide v2026.03 42 pages
GDPRData protection
You remain the controller. Since no data reaches us, no processing agreement is required. We supply a template regardless.
tom.pdf 11 pages as of 2026-02-18
eIDASTimestamps
Qualified timestamps under Article 42 eIDAS, from any provider you choose from the EU trusted list.
a-trust d-trust globalsign configurable
WORM storageIntegrity
Captures are written to object locked storage. Compliance mode prevents administrators from lifting the lock as well.
s3 object-lock compliance minio netapp tested
ImmutabilityIntegrity
Once sealed, a capture is read only. There is no edit mode, no exception and no emergency access.
no write api after seal code audit 2025-11
Audit trailAccountability
Every sign in, order, export and verification is appended to the log with the person's identifier and the time in UTC.
audit.log append-only hash chained
Roles and permissionsAccess
Four roles: read, capture, export, administer. Separation of capture and administration is enforced, second factor through your provider.
oidc ldaps scim webauthn
Penetration testSecurity
External test of the application and the containers by a Vienna testing lab, once a year. The full report is released on request.
report 2025-11-24 4 findings all closed
Retention and deletionLifecycle
Periods are set per matter. After expiry the software deletes on approval and writes a deletion log with the hashes of the deleted objects.
deletion-log-2026-q1.pdf signed
Documents for your review
You get these before you buy, with no non disclosure agreement and no call with sales.
Request the documentsTechnical and organisational measurespdf 11 p. 2026-02-18Installation guide and system requirementspdf 42 p. 2026-03-04Penetration test report, summarypdf 9 p. 2025-11-24Verification guide for seals and timestampspdf 6 p. 2026-01-30Sample evidence report, capture 4711pdf/a-3 14 p.List of subprocessorshtml 1 entry