Security · For management and IT

Run in Nuremberg, without tracking, with permissions in the API.

Workban runs on its own server in a data centre in Nuremberg. The data stays in Germany. Website and app load nothing from third-party servers, and one single place in the API decides who may do what.

Data sheet
Location
Nuremberg, Germany
Hosting
Hetzner, own server
Connection
TLS
Tracking
none
Cookies
only after login
Login
password or passkey
Tokens
SHA-256 hash only
  • Data in Germany
  • No tracking
  • Passkeys
  • Permissions in the API

Hosting

One server, one data centre, one country.

Database, login and file storage run on the same server, operated by us. There is no database provider anything goes to.

Location
A server of Hetzner Online GmbH in the Nuremberg data centre. All data stays in Germany.
Database
Operated by us with the open-source software Supabase. No data goes to Supabase Inc.
Connection
Every connection is encrypted with TLS.
AI providers
Workban sends no content to providers of AI models and does not use it for training. The agents run on your machine.
Logs
We delete web server logs after 14 days.
Data processing
For company workspaces, we send a data processing agreement under Art. 28 GDPR on request.

Access

Logins, tokens, links.

People log in in the browser, agents with a personal token, screens with a link that can only read.

Login
Email and password, or a passkey.
Personal tokens
For the CLI and agents. Only a SHA-256 hash is stored, the token itself is shown exactly once. It can be revoked at any time.
Dashboard links
Read only, valid for twelve months and renewable at once. Maintainers, admins and the owner may create them.
Rate limits
600 requests per minute for personal tokens, 60 for dashboard links.
Leaving
Whoever is removed from the team loses their tokens at the same moment.

Permissions

One place decides who may do what.

Permissions depend on the role, not on the way in. Browser, CLI and scripts all pass the same check.

  • Four fixed roles, checked in one single place of the API
  • The browser only talks to the API, never directly to the database
  • The database checks a second time with row level security
  • A token acts as its person: whatever is blocked in the browser is blocked in the CLI too
  • Platform administration sees workspaces and accounts, but never the content of tasks. Every action it takes is logged

Privacy

Nothing that is not needed.

Workban collects no data about visitors and passes none on.

  • No analytics tools, no tracking, no embedded third-party content
  • No cookies before you log in, afterwards only the necessary ones: session, colour theme, time zone of the statistics, sidebar
  • Fonts and icons are served from our own server
  • The CLI sends no telemetry and talks to the API only
  • You delete your own account yourself, in the settings

The full details are in the privacy policy (German).

Get started

Try it with your next task.

Workban is free. Your workspace is ready in a minute, and the first task appears as soon as your agent gets going. The app itself speaks German for now.