ISO/IEC 27001: The information security management system and external certification are in progress.
Security & self-hosting
Your data.Your infrastructure.
Pharen Hub can run as managed cloud, self-hosted or private deployment. You decide where workspace data lives, which models connect and which steps require human approval.
Standards & commitments
Clear status for security, privacy and open technology.
GDPR: Processes and deployments are being aligned with GDPR; the external review is planned for Q1 2027.
No model training: Workspace data is not used to train Pharen or generally available AI models. Third-party providers remain subject to their terms.
Open fair-code: The source code is inspectable and self-hostable. Fair-code combines transparency with sustainable product development.
Deployment models
Flexible deployment for your infrastructure.
Multi-tenant managed cloud: Operated by Pharen on Hetzner Cloud in the EU, including updates, backups and maintenance.
Standard · EUSingle-tenant managed cloud: A dedicated Pharen instance on Hetzner Cloud, fully operated by us.
Dedicated instanceBring your own cloud: A dedicated deployment in your Azure, AWS, Google Cloud or Hetzner environment.
Own environmentOn-premise: Run it in your data center or Kubernetes cluster, independently or together with Pharen.
Self or assistedReliable data foundation
Storage and deletion: In a self-hosted setup, you decide where workspace data lives, who can access it and when it is deleted.
Configurable data flows: Whether external models or integrations process data depends on your configuration.
Your operating standards: Backups, retention, network boundaries and logs can follow your internal requirements.
Security architecture
Bounded access: Roles and permissions control which content and tools people and agents can reach.
Human approvals: Critical actions can be tied to decisions and approval steps handled by people.
Traceable work: Tasks, decisions and workflows remain visible in the shared workspace context.
Compliance & risk
Fewer external parties: Self-hosting can simplify assessments because more processing stays in your controlled environment.
Reviewable foundation: Open fair-code and controllable deployments create a clearer basis for security reviews.
No automatic compliance: Whether a setup meets every requirement still depends on operations, contracts, providers and processes.
Models & integrations
Providers by configuration: Depending on the setup, Pharen can work with selected, customer-owned, self-hosted or OpenAI-compatible models.
Narrow permissions: Integrations should be enabled only for permitted data, use narrow scopes and be revoked when no longer needed.
Clear responsibility: The terms, locations and data paths of selected providers remain part of your review.
Governance & admin controls
Workspace-wide rules: Central settings control roles, access rights and permitted tools across the organization.
Human approvals: Critical actions can be tied to decisions and approval steps handled by people.
Traceable work: Tasks, decisions and workflows remain visible in the shared workspace context.
Legal documents
Transparency
Security needs foundations you can verify.
The open fair-code approach makes the technical direction visible and reduces dependency on a closed SaaS black box.
FAQ