Security · GDPR · Sovereignty

Security & Sovereignty

Six concrete technical pillars and one clear philosophy: every byte stays physically at your place, under your keys, under your jurisdiction.

  • 6 technical pillars
  • 0 data at our premises
  • 100 % local audit log
  • AES-256 disk encryption

Six pillars so your data stays your data

01

At-rest encryption

FileVault 2 · AES-XTS 256 · Secure Enclave key

The Mac Mini disk is encrypted with FileVault. The recovery key is generated and stored at your premises (and only there, in the local Keychain). No one, not even us, can read the disk without that key. If the Mac Mini is stolen, the data stays unreadable.

02

Tailscale · private VPN

WireGuard · curve25519 · ChaCha20-Poly1305 · per-device ACL

Remote access to your Mac Mini flows through an end-to-end encrypted Tailscale WireGuard tunnel. No port is exposed to the Internet, no public IP. Only you, from authorised devices, can connect. Self-hosted Headscale option available.

03

CrowdSec · IPS

YAML parsers + scenarios · community blocklist · /var/log/privatecore/crowdsec

CrowdSec watches intrusion attempts, port scans and anomalous behaviour. Known community attackers are blocked automatically before reaching your services. Your logs stay local, only anonymised attack signals are shared.

04

Caddy · auto TLS

TLS 1.3 only · Let's Encrypt ACME · HSTS preload · OCSP stapling

Caddy serves your web interface over HTTPS with Let's Encrypt certificates automatically renewed. Modern TLS versions are enforced, old ones disabled. No manual config, no forgotten or expired certificates.

05

Network VLAN

802.1Q tagging · router ACL · no inter-VLAN routing by default

Your pro Mac Mini lives on a VLAN separate from your home network. Personal devices (TV, consoles, IoT) cannot reach the pro layer, and vice versa. A compromised IoT device doesn't compromise your business data.

06

Uptime Kuma · monitoring

self-hosted · iOS/Android push · Slack/Teams webhooks

Uptime Kuma runs on your Mac Mini and monitors its own services (API, database, Ollama, Tailscale). On outage, you get an immediate email and push alert. Monitoring stays local, no third party gets notified.

Threat model : full transparency

We don't claim to protect against everything. Here's what we cover and what falls outside our scope.

Covered by PrivateCore

  • Physical Mac Mini theft (FileVault renders the disk unreadable)
  • Network interception (TLS 1.3 + end-to-end Tailscale WireGuard)
  • Brute force, scan, web exploits (CrowdSec + Caddy rate limiting)
  • Expired cert or weak TLS (Caddy automatic ACME)
  • Compromised IoT device on the network (VLAN isolation)
  • Silent service outage (Uptime Kuma + push alerts)

Out of scope : shared with other actors

  • macOS compromise itself (Apple 0-day RCE) : shared with Apple
  • Authenticated LAN attacker : your network operator
  • Foreign legal coercion : outside French jurisdiction, see legal notice
  • Human config mistake (leaving a weak password) : you stay admin

Native GDPR compliance

Because your data never leaves your Mac Mini, GDPR is satisfied by design. Data residency: France (your home or your office). No tracking, no third-party analytics, no advertising cookies. Right to erasure: unplug and destroy the disk : no copy lives in a datacenter. DPA (Data Processing Agreement) available on request for your B2B customers.

Audits & transparency

The BusinessCore source code is open for inspection by our customers under NDA. Binaries are signed with our Apple Developer ID certificate and notarized. Reproducible builds are on the roadmap. A detailed security report is provided at every pro install.

Responsible disclosure

Found a vulnerability? Email [email protected]. Optional PGP (key at /pgp.asc). First ack within 48h, fix or status within 30 days. Reporter list published at /security/hall-of-fame with your consent.

Email [email protected]

Ready to take back control?

A bespoke install, same-day reply, and your Mac Mini delivered in 24h.