European digital sovereignty

Your data stays in Europe, under your control

Goooy is self-hosted, so your organisation is the data controller, not a US hyperscaler. Your mail, files and meetings stay inside the EU, on infrastructure you choose and under access rules you set. For European organisations that turns GDPR compliance from something you outsource and take on trust into something you can demonstrate.

Open source Open standards Encryption in transit Granular access control One directory & sign-in Your data residency
EU data sovereignty

Your data never leaves the EU, or your boundary

Because you run Goooy, no third-party processor sits in the loop and no foreign provider holds a copy of your content. That is what GDPR, and every European procurement checklist, asks about first.

  • You are the data controller. Goooy has no access to your content, and there's no data-processing agreement to sign with us

  • Keep everything inside the EU: pin mail, files, calendars and metadata to an EU region, or on-premise in your own datacentre

  • Beyond the reach of the US CLOUD Act and foreign data requests: no American hyperscaler ever holds a copy

  • No vendor telemetry, no phone-home; open source (AGPL), auditable and free of lock-in

Defence in depth

Security built into every layer

The same controls a CISO expects from an enterprise suite (encryption, strong identity, audit trails and hardened operations), shipped in the box and verifiable in the open-source code.

Encryption

  • TLS in transit across web, API, mail and backing stores
  • Secrets sealed at rest with AES-256-GCM
  • End-to-end encrypted email with S/MIME
  • Opt-in end-to-end encryption for individual chat conversations

Access & identity

  • Role-based access control with organisation-scoped multi-tenancy
  • Single sign-on via OIDC and SAML 2.0
  • MFA with TOTP and WebAuthn / FIDO2 passkeys

Account-takeover protection

  • Per-IP rate limiting plus per-account lockout with backoff
  • Have I Been Pwned breach checks on passwords
  • Login audit log and new-device sign-in alerts

Mail security & anti-phishing

  • Rspamd spam filtering, with the verdict honoured at delivery
  • Deceptive-link, homograph and impersonation detection
  • Remote content blocked and proxied by default
  • Links rewritten so a URL is checked when it's clicked, and attachments opened in a sandbox first

Auditability

  • Append-only admin and login audit trails
  • Fully open-source code, independently auditable
  • End-to-end test suites covering every module

Operational hardening

  • Non-root containers, dropped Linux capabilities, seccomp
  • Scoped CORS, strict security headers and HSTS
  • Scheduled database backups with retention control

Data governance & compliance

  • Per-organisation retention policies that age out mail, files and messages on your schedule
  • Legal hold to preserve records under investigation or litigation, overriding retention until it's lifted
  • Org-wide data-loss-prevention scanning across mail, chat and files
  • A custodian's mail, files and messages exported as JSON for eDiscovery, with the export itself audit-logged

Mail authentication & reporting

  • SPF, DKIM and DMARC published and signed for every domain you host
  • DMARC aggregate reports parsed on arrival into pass-rate, alignment and spoofing-source views
  • MTA-STS policy hosting and SMTP TLS reporting, so downgrade attacks stop being invisible

Provisioning & tokens

  • SCIM 2.0 and LDAP/Active Directory sync create, update and disable accounts from your directory
  • Goooy issues OAuth2/OIDC tokens for your other apps; they're opaque and revocable, not self-validating
  • App passwords give an older client its own credential you can revoke without touching the account

Tenant isolation

  • Every organisation is scoped in the query layer, not per route, so a missed check can't leak across tenants
  • Optional hard isolation: a PostgreSQL schema, or an entire database, per tenant
  • Background workers, protocol endpoints and inbound mail delivery all resolve the tenant the same way
Straight answers

What we claim, and what we don't

Here is where Goooy stands on certifications, including the parts we cannot claim.

Not certified, by design

Goooy is not ISO 27001, SOC 2 or HIPAA certified. Because you host it, certification attaches to your deployment and your processes. We give you the controls; you certify against your own framework.

GDPR building blocks

We provide the building blocks for GDPR: data residency, encryption, access control, audit logs, export and deletion. Meeting your obligations as controller stays your job, and the docs show how.

On the roadmap

The code is open for independent review today; commissioned third-party audits and a published security policy are on the roadmap, not yet done.

Evaluate it against your own policy

Read the full security and data-sovereignty documentation, or bring your security team's questions straight to us.