Trust & security
Security & data protection at DataLion
Market research means sensitive respondent data. DataLion protects it with hosting in ISO 27001-certified data centers in Germany, encrypted transport and granular access control. The DPA under Art. 28 GDPR is included.
DataLion is hosted in ISO 27001-certified data centers in Germany (Hetzner), encrypts all traffic with TLS and backs up its database hourly. The Data Processing Agreement under Art. 28 GDPR is included. Roles and granular access profiles control who sees what; two-factor authentication and SSO can be enabled. On-premise deployment is available.
- 🇩🇪 Made in Munich
- GDPR-compliant
- DPA included
- Hosted in Germany
- 🌐 Interface in EN, DE, FR & NL
Trusted by research institutes, brands & insights teams
- 50+ interactive chart types
- 20+ statistical methods
- SPSS · Excel · CSV import without data loss
- ISO 27001 certified data centers (Germany)
Hosting in ISO 27001-certified data centers
DataLion is hosted with Hetzner Online GmbH in Germany, at the Nuremberg and Falkenstein locations. The data centers are ISO 27001-certified; the certification applies to the data centers and the hosting, not to DataLion as a company or software. The hosting is climate-neutral.
Your data is processed and stored in Germany. A data processing agreement under Art. 28 GDPR is in place with the hosting provider. For enterprises, institutes and the public sector this means short paths, German law, and no third-country transfer of respondent data through the hosting.
- Hetzner, Nuremberg and Falkenstein locations
- ISO 27001-certified data centers (certification of the hosting, not of DataLion)
- Climate-neutral hosting
- Data stays in Germany
Backups: hourly incremental, daily full
The database is backed up incrementally every hour and in full every day. Backups are kept for seven days. If the worst happens, a recent state is ready to restore.
You can check the current operational status of the platform publicly at any time: status.datalion.
- Hourly incremental database backups
- Daily full backup
- Seven-day retention
- Public status page
Encryption & hardening
All connections to DataLion are TLS-encrypted (HTTPS), with HSTS and security headers such as X-Frame-Options and restrictive referrer and permissions policies. Session cookies are encrypted, HttpOnly and Secure.
Passwords are stored only as salted hashes, never in plain text; a password history prevents reusing old passwords. Particularly sensitive stored values (2FA secrets, stored AI API keys) are additionally encrypted at the application level with AES-256.
Login attempts and API access are rate-limited to slow down brute-force and abuse attempts. On request, access can be restricted to fixed IP ranges, such as your corporate network.
Development itself is secured, too: every code change runs through automated security scans covering static code analysis (SAST), dependency audits and secret scanning.
- TLS/HTTPS with HSTS and security headers
- Encrypted, HttpOnly and Secure session cookies
- Passwords stored only as salted hashes, with password history
- AES-256 encryption of stored secrets (2FA, API keys)
- Rate limiting for logins and API, IP restriction available
- Automated security scans in the development pipeline (SAST, dependencies, secrets)
Roles, permissions & access profiles
DataLion controls access on three levels: roles (admin, editor, viewer), per-dashboard permissions (edit, view, no access) and granular per-project access profiles. These determine who may see, filter, export or share data, down to read-only client accounts and row-level data filters via access profiles.
Technically, a strict principle applies: every resource is protected by an access policy that denies by default (fail-closed). That every single data model actually carries such a policy is verified automatically with every release.
More detail on the roles & permissions and access profiles pages.
- Roles: admin, editor, viewer
- Permissions per dashboard and report
- Per-project access profiles: export, filter and sharing rights, read-only accounts
- Row-level data filters via access profiles
- Fail-closed access policies, automatically verified with every release
Support access: only with your approval, fully logged
Access by DataLion itself is regulated, too: support access to your environment runs through an audited support access system. You set the mode: disabled, approval per case, or standing permission.
Every support session is bound to an SSO-verified @datalion.com identity, limited to 45 minutes and immediately revocable at any time. A complete access log records which staff member accessed what and when, and a banner shows the active support session while it runs.
- Three modes: disabled, approval per case, standing permission
- SSO-verified staff identity (@datalion.com)
- Sessions limited to 45 minutes, immediately revocable
- Complete access log including the personal identity
Two-factor authentication & single sign-on
Beyond email and password, DataLion supports two-factor authentication (TOTP) via authenticator app. It can be enabled per user or made mandatory for the entire installation.
For password-less login, single sign-on via Google or Microsoft (OAuth) and via the DataLion Identity Server can be enabled. Enterprise customers connect their own identity provider. Details on the single sign-on page.
- TOTP 2FA via authenticator app, optionally mandatory
- SSO via Google and Microsoft (OAuth)
- DataLion Identity Server
- Own identity provider for Enterprise
GDPR & Data Processing Agreement
DataLion is a German company and operates 100% GDPR-compliant. You receive the Data Processing Agreement (DPA) under Art. 28 GDPR digitally, right away, with no lengthy negotiation. For Enterprise customers it is individually negotiable.
Our service providers are chosen EU-first, too: hosting with Hetzner in Germany, email delivery and product analytics on EU instances. All details, legal bases and sub-processors are transparently documented in our privacy policy.
Data minimisation applies internally as well: usage activity is recorded only as a coarse daily signal without project, content or IP reference, and pruned automatically.
- DPA under Art. 28 GDPR included digitally
- Enterprise: DPA individually negotiable
- EU-first service providers and sub-processors
- Data-minimal activity signals with no project, content or IP reference
- Transparent privacy policy
AI features with a configurable endpoint
For AI features like "Ask your data" and sentiment & topic analysis, each workspace stores its own AI model: its own key, its own model, its own endpoint, chosen from HybridAI, OpenAI, Anthropic, Azure OpenAI and Mistral. The endpoint is freely configurable, and EU or on-premise operation of the language model is possible. Stored API keys are encrypted.
The Claude / MCP integration starts read-only: write access requires an explicit setting, API tokens are scoped, and debug logs are redacted.
- Bring your own model: HybridAI, OpenAI, Anthropic, Azure OpenAI, Mistral
- Freely configurable endpoint, EU/on-premise possible
- AI keys stored encrypted
- MCP connection read-only by default, scoped API tokens
On-premise & dedicated hosting
If your compliance requires it, run DataLion on-premise in your own infrastructure (a Docker-based installation with a license key) or as a dedicated instance on separate hardware in Germany. You keep full control over location, operation and data flows.
Behind all of this is a German company: made in Munich, with German-language support and contacts who know the requirements of European market research.
- On-premise as a Docker-based installation
- Dedicated hosting on a separate instance
- Made in Munich, German-language support
See DataLion with your own data
Start free with your own raw data. Or book a personal demo of the path to a finished dashboard.
What users say about DataLion
- via G2
Very professional company, attentive to the customer needs, provider of a great software and service.
Generoso M. · CRM Analyst, Automotive - via G2
The contacts at DataLion are very committed. If you have problems, you can count on help. DataLion reacts quickly to requests for new functions.
Robert Q. · Managing Director - via G2
User-friendliness, especially for market research topics. Structured backend with many customization options.
Verified user · Market Research - via G2
The embedding function allows us to generate insights of our data for our audience and customers by far less than half of the usual time needed before.
Verified user · Leisure, Travel & Tourism
We now work much more efficiently, giving us more time to take care of the derivations and insights from the data for the customers.
Security in DataLion: the feature pages
Common questions about security
Where is my data stored?
Is DataLion ISO 27001-certified?
Is there a Data Processing Agreement (DPA)?
Does DataLion support two-factor authentication and SSO?
How often are backups created?
What happens to my data when I use the AI features?
Can I run DataLion in my own infrastructure?
Can DataLion staff access my data?
Secure market research from Germany
Try DataLion for free, or get a personal demo with a detailed walkthrough of the security setup.