Security · GDPR · Sovereignty

Security & Sovereignty

Six concrete technical pillars and one clear rule: your data stays in your own instance, in France, online or at your place on a Mac mini.

  • 6 technical pillars
  • 0 data at our premises with the Mac mini
  • 100% local audit log
  • AES-256 disk encryption

Six pillars so your data stays your data

01

At-rest encryption

FileVault 2 · AES-XTS 256 · Secure Enclave key

The Mac Mini disk is encrypted with FileVault. The recovery key is generated and stored at your premises. No one, not even us, can read the disk without that key. If the Mac Mini is stolen, the data stays unreadable.

02

Tailscale · private VPN

WireGuard · curve25519 · ChaCha20-Poly1305 · per-device ACL

Remote access to your Mac Mini flows through an end-to-end encrypted Tailscale WireGuard tunnel. No port is exposed to the Internet, no public IP. Only you, from authorised devices, can connect.

03

Throttled attempts

rate limiting in the application · fail2ban and ufw firewall (online)

The application slows down repeated logins: past a threshold, attempts are refused. Online, the server also blocks addresses that keep trying and closes every unused port.

04

Caddy · auto TLS

TLS 1.2 and 1.3 · Let's Encrypt ACME · HSTS · OCSP stapling

Caddy serves your web interface over HTTPS with Let's Encrypt certificates automatically renewed. Modern TLS versions are enforced, old ones disabled. No manual config, no forgotten or expired certificates.

05

Separate network, recommended

VLAN · depends on your router

With the Mac mini, we recommend placing it on a network (VLAN) separate from your personal devices, if your router allows it: a hacked connected device then cannot reach your business data. It is a router setting, not a protection PrivateCore sets up on its own.

06

Health checks

/health · /health/ready · /health/detailed (admin)

The application exposes check points (service, database) that a monitoring tool can query at regular intervals. The monitoring tool and its alerts are not supplied by default.

Threat model: full transparency

We don't claim to protect against everything. Here's what we cover and what falls outside our scope.

Covered by PrivateCore

  • Physical Mac Mini theft (FileVault renders the disk unreadable)
  • Network interception (TLS 1.3 + end-to-end Tailscale WireGuard)
  • Brute force on login (attempt limiting in the application)
  • Expired cert or weak TLS (Caddy automatic ACME)

Out of scope: shared with other actors

  • macOS compromise itself (Apple 0-day RCE): shared with Apple
  • Authenticated LAN attacker: your network operator
  • Hacked connected device on your network: your network (separate network recommended)
  • Foreign legal coercion: outside French jurisdiction, see legal notice
  • Human config mistake (leaving a weak password): you stay admin

Native GDPR compliance

Your data stays in your own instance, in France: on our servers with the online plan, within your walls with the Mac mini. No tracking, no third-party analytics, no advertising cookies in the application. Your data exports in standard formats (CSV, PDF, FEC accounting file). DPA (Data Processing Agreement) available on request for your B2B customers.

Transparency

PrivateCore is not open source software: it is built on proven open source components (Ollama, FastAPI, SQLAlchemy, React). Your data leaves in standard formats (CSV, PDF, FEC accounting file) and, on a Mac Mini, the Mac stays yours with your data.

Responsible disclosure

Found a vulnerability? Email security@privatecore.fr. First acknowledgement within 48 hours, then coordinated disclosure.

Email security@privatecore.fr

Ready to take back control?

A bespoke install, an answer from the founder, and a Mac Mini you buy yourself or we deliver configured.