Skip to content
Security and GDPR

Security and GDPR for your document archive.

A separate data space for each company, permissions by category and by document, an audit log of every action, sign-in with MFA or your company account. Standard mechanisms, applied everywhere: search, chat and the wiki included.

Audit log · latest events
  • 14:32Approved · step 1 · Acme contract v3
  • 14:30Downloaded · Acme contract v3
  • 14:28New version · v2 → v3 · “SLA updated”
  • 14:25Share link created · expires in 7 days
  • 14:11Sign-in · MFA verified
Separate spaces

Every company in its own space.

Each organisation has its own separate data space in the database, its own storage, its own AI configuration, its own users and its own knowledge. The separation is built into the architecture, not a rule that can be forgotten.

Separate data

A company's documents, facts and configuration live in a space of their own: they cannot be reached from another company.

Own configuration

Connectors, models, spending caps, knowledge visibility, categories and document types: each company has its own.

People in several companies

A consultant can work for several companies: each membership is explicit, with its own roles.

Permissions

Who sees what, down to the single document.

Roles defined by the administrator, permissions by category, explicit access to a document and private or company-wide visibility. The same rule applies to search, chat, the wiki and the API.

  • Custom roles: reviewer, approver, read-only
  • An API key has a role that limits its permissions
  • Knowledge facts inherit the permissions of the document they come from

DAM administrator

vieweditmanageadministeraudit log

Editor

viewedit

Reader

view

Reviewer (custom)

viewaudit log
Audit log

Every action leaves a trace.

Approvals, new versions, downloads, shares, sign-ins, configuration changes: everything goes into the audit log with person, date and object, and can be filtered by user, type and period.

Document workflow

Who approved, rejected or signed, at which step and with which comment.

Document use

Who downloaded or shared a document, and when.

Configuration

Who changed permissions, connectors or AI settings.

Sign-in

MFA, company account, verified email.

Sign in with a verified email and password, or with your company's Microsoft or Google account. Two-factor verification adds an extra step.

Two-factor verification

A second verification step at sign-in, with an authenticator app.

Microsoft and Google

Sign-in via OAuth 2.0: passwords stay with the identity provider, and Theka does not see them.

Verified email

Anyone who signs up with email confirms their address before entering a company space.

Data and AI

Your documents stay under your control.

Data in the EU, your own storage

The servers are in the EU; files can stay in your own storage, in your jurisdiction. You export and delete everything whenever you want.

AI only where you enable it

AI tasks are enabled by category: without enabling them, no content goes to an external provider. You use your own key, under the terms of your own contract.

Search on your own cluster

With your own Elasticsearch or OpenSearch, the text indexed for search can stay only on your cluster; permissions are still enforced by Theka.

On-premise

For healthcare, finance, public administration and defence, Theka can be installed on your servers or in your private cloud.

Governance

Approvals and signatures as evidence.

A signed document has gone through its steps with recorded decisions: its history can be reconstructed at any time, from upload to signature.

01Who uploaded each version, and when
02Who approved at which step, with which comment
03Who signed, in which order, with the signed PDF attached
04Chat conversations are saved together with the cited sources
Frequently asked questions

On security and privacy.

Where is the data?

On servers in the EU. Files can stay in your own storage (S3, SharePoint, MinIO, SFTP) and you can export or delete them whenever you want.

Can one company see another company's data?

No. Each company has its own separate data space in the database, with its own configuration, users and knowledge.

Can the AI see documents the user cannot open?

No. Search, chat and the wiki go through the same permission check: the AI only works on what the user can open.

Can I keep document text outside Theka?

With your own search engine (Elasticsearch or OpenSearch), the text indexed for search can stay only on your cluster. For the strictest requirements there is also an on-premise installation.

// contact

Let's try Theka
on your archive.

A 30-minute call for a guided demo and an initial assessment of how well Theka fits the way you work.