GDPR-Compliant IT Inventory Management
Notory is an IT inventory and asset management solution that you can run self-hosted in Germany/the EU or as EU-hosted SaaS. Sensitive data is encrypted field-by-field with AES-256-GCM, tenant isolation is secured fail-closed via row-level security, and every change lands in a tamper-proof audit log. The security controls are aligned with ISO 27001 and BSI C5.
Data sovereignty through self-hosting
Run it via Docker, VM or Kubernetes with PostgreSQL or MariaDB - even against an existing, external database. The licence is checked offline against your instance ID. No data is shared with third parties.
Encryption per BSI TR-02102
Field-based AES-256-GCM encryption of secrets at rest (SSO secrets, 2FA seeds, webhook secrets); TLS in transit. A cryptography concept documents where which encryption applies.
Tenant isolation (fail-closed)
Row-level security at the database level: without a set tenant context, no data is visible - a forgotten filter does not lead to a data leak. Ideal for service providers with multiple customers.
Tamper-proof audit log
Every write action is logged; entries are secured via a hash chain, so subsequent changes or deletions are detectable. Retention periods are configurable (storage limitation).
Questions about GDPR compliance
Where is my data stored?
You decide: self-hosted on your own infrastructure for full data sovereignty, or as SaaS hosted by us in the EU. No sharing with third parties.
How does Notory support accountability?
Through the tamper-proof audit log (hash chain) plus configurable retention periods and role-based access control.
Is Notory also suitable for public authorities/schools?
Yes - self-hosting in the EU, controls aligned with ISO 27001 / BSI C5, and multi-tenancy make Notory a good fit for the public sector too.
Inventory the GDPR-compliant way
Start with Starter from EUR 10 net/month or request a live demo.