---
title: "Enterprise trust & procurement"
canonical: https://wavect.io/trust-center/
language: en
description: "Wavect's trust center: legal entity, IP ownership, DPA, EU data residency, subprocessors, access control, incident handling, handover, key-person continuity, …"
image: "https://wavect.io/img/general/bak/open_graph_preview.jpg"
---

Enterprise trust & procurement

# Everything procurement and security need before they sign

The commercial, legal and security answers a due-diligence checklist asks for, gathered on one page. Where the full detail lives elsewhere on this site, we link straight to it. No sales gloss, no claims we cannot back.

At a glance 1 page for the whole vendor review

In one sentence

Wavect GmbH is an Austrian software company you can contract with under Austrian law, where you own all IP from day one, your data stays EU-resident by default, and a two-founder team plus vetted bench means work survives any single person leaving.

Straight answers on

- Legal entity, contracting jurisdiction and IP ownership
- Data-processing agreements, EU data residency and subprocessors
- Access control, backup, incident handling and handover
- Key-person continuity, support models and response times

What we will not pretend

- We do not hold ISO 27001, SOC 2 or a formal security certification today
- We do not offer a 24/7 network operations center or an uptime SLA
- We are a small senior team, not a large managed-service vendor

For the delivery path behind these controls, review our [enterprise delivery and governance pathway](/enterprise/).

// 01

## The procurement checklist, answered

Each row gives you the short answer and a link to the page that documents it in full.

| Topic | Where we stand | Documented in |
| --- | --- | --- |
| Legal entity & jurisdiction | Wavect GmbH, FN 575337 i, Landesgericht Innsbruck, UID ATU77948526, seated in Ampass, Tirol. Founded 2018 as Wavect e.U., a GmbH since 2022. Contracts default to Austrian law; we have also signed under German, Swiss, US and Singaporean law. | [Imprint & service agreement](/imprint/) |
| IP ownership | You own everything we build. Full IP transfer, no rights retained by us, code in your repository from day one. | [Service agreement](/agb/) |
| Handover | A complete handover is the default, not an upsell: code, credentials, documentation and runbooks transferred, with keys rotated to you. | [Handover checklist](/software-development-guide/software-handover-checklist/) |
| Key-person continuity | Two founders on every engagement, plus a vetted specialist bench. We have handed work off cleanly dozens of times; the team is bigger than any one person. | [About the team](/about/) |
| Use of external specialists | Specialists join under our statement of work as subcontractors, vetted before they touch your project. One contract with us, one invoice, chain-of-processors confidentiality in place. | [Expert network](/experts/) |
| Hosting & data residency | EU hosting by default. Your data stays under EU and Austrian rules unless your project requires something else, which we confirm up front. | [EU data residency guide](/blog/eu-data-residency-ai-apps-2026/) |
| GDPR & privacy | GDPR and Austrian DSG compliant. Our data protection officer is Kevin Riedl. Legal bases, retention and third parties are set out in full. | [Privacy policy](/imprint/#privacy) |
| Support & maintenance | Maintenance is optional, never baked in. Fixed price on a signed Werkvertrag, or a monthly retainer you can cancel weekly with no notice period. | [Fixed price vs time & materials](/software-development-guide/fixed-price-vs-time-and-materials/) |

// 02

## Subprocessors

The third parties that process data for wavect.io itself. For client projects, infrastructure and subprocessors are chosen per engagement and are EU-resident by default; we list them in that project’s data-processing agreement.

| Subprocessor | Purpose | Data | Location |
| --- | --- | --- | --- |
| Cloudflare | Static site hosting and CDN for wavect.io | Request logs, IP addresses | Global edge, EU data centers |
| Umami | Cookieless website analytics | No personal data | Germany (EU) |
| PostHog EU | Product analytics, session and funnel data | Usage events | Germany (EU) |
| Zeeg (Zeeg GmbH) | Call scheduling from the booking links | Name, email, selected time | Germany (EU) |

This list changes when our tooling changes. If you need advance notice of subprocessor changes for a signed engagement, we can add that to the contract.

// 03

## Security & delivery posture

The topics a security questionnaire asks about that did not have a dedicated home elsewhere. These are honest statements of how a small senior team actually operates, not aspirational policy.

Data-processing agreement

We sign your data-processing agreement, or provide an Art. 28 GDPR agreement of our own that covers the full chain of subprocessors. Raise it on the first call and it is in place before any personal data is processed. For client builds, the DPA is part of the engagement paperwork, not an afterthought.

Access-control practices

We work inside the repositories and infrastructure you grant us, with access you can revoke at any time. Least privilege by default, per-project credentials, multi-factor authentication on our accounts, and no shared logins. At handover, every credential is rotated to you so nothing we held still opens a door.

Backup & recovery

For client projects, backup and disaster recovery are designed into the build: tested restores and documented runbooks, owned by you after handover so recovery never depends on us being reachable. For our own systems, source lives in version control and infrastructure is reproducible from code.

Incident handling

You get a named contact who stays reachable, not a ticket queue. Our job during an incident is to triage, communicate clearly and fix. We are honest about the ceiling: we do not run a 24/7 network operations center, and ongoing on-call response is what a retainer buys.

Documentation standards

Every build hands over an architecture overview, setup instructions, deploy and rollback steps, and runbooks. Documentation lives in your repository next to the code, so it stays with the software rather than in a tool you lose access to. The [handover checklist](/software-development-guide/software-handover-checklist/) is the full standard.

Insurance & certifications

Wavect holds professional indemnity insurance. We will also be straight about certifications: we do not currently hold ISO 27001 or SOC 2 certification. What stands in their place is structural, not a badge: a small senior team, your code in your repository from day one, a complete handover that removes lock-in, and a contract under Austrian law that binds us to what we agreed. If a specific certification is a hard procurement gate, tell us early and we will tell you plainly whether we can meet it rather than claiming we already do.

Service levels

We reply within four working hours, usually within one. Ongoing support runs on a retainer with a defined weekly commitment you can cancel without notice. We do not sell an uptime SLA: availability and reliability for delivered software are scoped per engagement, consistent with our [service agreement](/agb/), so we never promise a number we would not stand behind.

## Procurement questions, answered plainly

### Which legal entity do we contract with, and under what law?

Wavect GmbH, an Austrian company registered as FN 575337 i at the Landesgericht Innsbruck, UID ATU77948526, seated in Ampass, Tirol. Austrian law is the default, and we can sign under your standard master agreement. We have also contracted under German, Swiss, US and Singaporean law.

### Do we own the IP and the source code?

Yes, fully. All IP in what we build transfers to you, we retain no rights, and the code lives in your repository from the first commit. This is written into the service agreement, not just promised.

### Will you sign a data-processing agreement?

Yes. We sign your DPA or provide an Art. 28 GDPR agreement covering the full subprocessor chain. It is in place before any personal data is processed.

### Who are your subprocessors?

For wavect.io itself: Cloudflare for hosting, Umami and PostHog EU for analytics, and Zeeg for scheduling, all EU-resident. For client projects, subprocessors are chosen per engagement, EU-resident by default, and listed in that project’s DPA.

### What happens if the person leading our project leaves?

Work does not stop. Two founders sit on every engagement and a vetted bench backs them up, so knowledge is never held by one person. We have handed projects off cleanly dozens of times, and the handover discipline that makes that possible is the same one we use at the end of every build.

### Do you hold professional indemnity insurance, ISO 27001 or SOC 2?

We hold professional indemnity insurance. We do not currently hold ISO 27001 or SOC 2 certification, and we will not claim otherwise. What protects you beyond our insurance is structural: a small senior team, your code in your repository from day one, a complete handover that removes lock-in, and an Austrian-law contract that binds us to delivery. If a certification is a hard requirement for your procurement process, tell us early and we will be honest about whether we can meet it.

### What are your service levels and support options?

We reply within four working hours, usually within one. Ongoing support is a monthly retainer with a defined weekly commitment, cancellable without notice. We do not offer an uptime SLA; availability for delivered software is scoped per engagement so we never promise a number we cannot stand behind.

Last reviewed: 2026-07-17 by [Christof Jori](/team/christof-jori/) [wiki ↗](https://www.wikidata.org/wiki/Q139796367)

## Structured Data

```json
{
  "@context": "https://schema.org",
  "@graph": [
    {
      "@id": "https://wavect.io/#organization",
      "@type": [
        "Organization",
        "ProfessionalService",
        "LocalBusiness"
      ],
      "employee": [
        {
          "@id": "https://wavect.io/team/kevin-riedl/#person",
          "@type": "Person",
          "jobTitle": "Managing Director",
          "name": "Kevin Riedl",
          "url": "https://wavect.io/team/kevin-riedl/",
          "worksFor": {
            "@id": "https://wavect.io/#organization",
            "@type": [
              "Organization",
              "ProfessionalService",
              "LocalBusiness"
            ]
          }
        },
        {
          "@id": "https://wavect.io/team/christof-jori/#person",
          "@type": "Person",
          "jobTitle": "Managing Director",
          "name": "Christof Jori",
          "url": "https://wavect.io/team/christof-jori/",
          "worksFor": {
            "@id": "https://wavect.io/#organization",
            "@type": [
              "Organization",
              "ProfessionalService",
              "LocalBusiness"
            ]
          }
        }
      ],
      "founder": [
        {
          "@id": "https://wavect.io/team/kevin-riedl/#person",
          "@type": "Person",
          "jobTitle": "Managing Director",
          "name": "Kevin Riedl",
          "url": "https://wavect.io/team/kevin-riedl/",
          "worksFor": {
            "@id": "https://wavect.io/#organization",
            "@type": [
              "Organization",
              "ProfessionalService",
              "LocalBusiness"
            ]
          }
        },
        {
          "@id": "https://wavect.io/team/christof-jori/#person",
          "@type": "Person",
          "jobTitle": "Managing Director",
          "name": "Christof Jori",
          "url": "https://wavect.io/team/christof-jori/",
          "worksFor": {
            "@id": "https://wavect.io/#organization",
            "@type": [
              "Organization",
              "ProfessionalService",
              "LocalBusiness"
            ]
          }
        }
      ],
      "legalRepresentative": [
        {
          "@id": "https://wavect.io/team/kevin-riedl/#person",
          "@type": "Person",
          "jobTitle": "Managing Director",
          "name": "Kevin Riedl",
          "url": "https://wavect.io/team/kevin-riedl/",
          "worksFor": {
            "@id": "https://wavect.io/#organization",
            "@type": [
              "Organization",
              "ProfessionalService",
              "LocalBusiness"
            ]
          }
        },
        {
          "@id": "https://wavect.io/team/christof-jori/#person",
          "@type": "Person",
          "jobTitle": "Managing Director",
          "name": "Christof Jori",
          "url": "https://wavect.io/team/christof-jori/",
          "worksFor": {
            "@id": "https://wavect.io/#organization",
            "@type": [
              "Organization",
              "ProfessionalService",
              "LocalBusiness"
            ]
          }
        }
      ],
      "name": "Wavect GmbH",
      "subjectOf": {
        "@id": "https://wavect.io/verified-claims.json#dataset",
        "@type": "Dataset",
        "creator": {
          "@id": "https://wavect.io/#organization",
          "@type": [
            "Organization",
            "ProfessionalService",
            "LocalBusiness"
          ]
        },
        "description": "A machine-readable registry of quantitative and qualitative claims published by Wavect, with review dates, localized page appearances and public third-party citations where available.",
        "inLanguage": "en",
        "isAccessibleForFree": true,
        "license": "https://creativecommons.org/licenses/by/4.0/",
        "name": "Wavect verified publication claims",
        "url": "https://wavect.io/verified-claims.json"
      },
      "url": "https://wavect.io/"
    },
    {
      "@id": "https://wavect.io/team/kevin-riedl/#person",
      "@type": "Person",
      "jobTitle": "Managing Director",
      "name": "Kevin Riedl",
      "sameAs": [
        "https://www.wikidata.org/wiki/Q139796365",
        "https://www.linkedin.com/in/wsdt",
        "https://github.com/wsdt"
      ],
      "url": "https://wavect.io/team/kevin-riedl/",
      "worksFor": {
        "@id": "https://wavect.io/#organization",
        "@type": [
          "Organization",
          "ProfessionalService",
          "LocalBusiness"
        ]
      }
    },
    {
      "@id": "https://wavect.io/team/christof-jori/#person",
      "@type": "Person",
      "jobTitle": "Managing Director",
      "name": "Christof Jori",
      "sameAs": [
        "https://www.wikidata.org/wiki/Q139796367",
        "https://www.linkedin.com/in/jocr77/",
        "https://github.com/jo-chris"
      ],
      "url": "https://wavect.io/team/christof-jori/",
      "worksFor": {
        "@id": "https://wavect.io/#organization",
        "@type": [
          "Organization",
          "ProfessionalService",
          "LocalBusiness"
        ]
      }
    },
    {
      "@id": "https://wavect.io/#website",
      "@type": "WebSite",
      "inLanguage": [
        "en",
        "de",
        "es",
        "zh"
      ],
      "name": "Wavect",
      "potentialAction": {
        "@type": "SearchAction",
        "query-input": "required name=search_term_string",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://wavect.io/search/?q={search_term_string}"
        }
      },
      "publisher": {
        "@id": "https://wavect.io/#organization",
        "@type": [
          "Organization",
          "ProfessionalService",
          "LocalBusiness"
        ]
      },
      "url": "https://wavect.io/"
    }
  ]
}
```

```json
{
  "@context": "https://schema.org",
  "@graph": [
    {
      "@id": "https://wavect.io/trust-center/#webpage",
      "@type": "WebPage",
      "about": {
        "@id": "https://wavect.io/#organization",
        "@type": [
          "Organization",
          "ProfessionalService",
          "LocalBusiness"
        ]
      },
      "author": {
        "@id": "https://wavect.io/team/kevin-riedl/#person",
        "@type": "Person",
        "name": "Kevin Riedl",
        "url": "https://wavect.io/team/kevin-riedl/"
      },
      "dateModified": "2026-07-17",
      "description": "Wavect's trust center: legal entity, IP ownership, DPA, EU data residency, subprocessors, access control, incident handling, handover, key-person continuity, support and service levels, in one place for procurement and security reviews.",
      "headline": "Everything procurement and security need before they sign",
      "inLanguage": "en",
      "isPartOf": {
        "@id": "https://wavect.io/#website",
        "@type": "WebSite"
      },
      "lastReviewed": "2026-07-17",
      "name": "Everything procurement and security need before they sign",
      "reviewedBy": {
        "@id": "https://wavect.io/team/christof-jori/#person",
        "@type": "Person",
        "name": "Christof Jori",
        "url": "https://wavect.io/team/christof-jori/"
      },
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          ".sp-hero__h1--xl",
          ".sp-hero__lead"
        ]
      },
      "url": "https://wavect.io/trust-center/"
    },
    {
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "item": "https://wavect.io/",
          "name": "Home",
          "position": 1
        },
        {
          "@type": "ListItem",
          "item": "https://wavect.io/trust-center/",
          "name": "Trust center",
          "position": 2
        }
      ]
    }
  ]
}
```

```json
{
  "@context": "https://schema.org",
  "@type": "FAQPage",
  "mainEntity": [
    {
      "@type": "Question",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Wavect GmbH, an Austrian company registered as FN 575337 i at the Landesgericht Innsbruck, UID ATU77948526, seated in Ampass, Tirol. Austrian law is the default, and we can sign under your standard master agreement. We have also contracted under German, Swiss, US and Singaporean law."
      },
      "name": "Which legal entity do we contract with, and under what law?"
    },
    {
      "@type": "Question",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Yes, fully. All IP in what we build transfers to you, we retain no rights, and the code lives in your repository from the first commit. This is written into the service agreement, not just promised."
      },
      "name": "Do we own the IP and the source code?"
    },
    {
      "@type": "Question",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Yes. We sign your DPA or provide an Art. 28 GDPR agreement covering the full subprocessor chain. It is in place before any personal data is processed."
      },
      "name": "Will you sign a data-processing agreement?"
    },
    {
      "@type": "Question",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "For wavect.io itself: Cloudflare for hosting, Umami and PostHog EU for analytics, and Zeeg for scheduling, all EU-resident. For client projects, subprocessors are chosen per engagement, EU-resident by default, and listed in that project's DPA."
      },
      "name": "Who are your subprocessors?"
    },
    {
      "@type": "Question",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Work does not stop. Two founders sit on every engagement and a vetted bench backs them up, so knowledge is never held by one person. We have handed projects off cleanly dozens of times, and the handover discipline that makes that possible is the same one we use at the end of every build."
      },
      "name": "What happens if the person leading our project leaves?"
    },
    {
      "@type": "Question",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "We hold professional indemnity insurance. We do not currently hold ISO 27001 or SOC 2 certification, and we will not claim otherwise. What protects you beyond our insurance is structural: a small senior team, your code in your repository from day one, a complete handover that removes lock-in, and an Austrian-law contract that binds us to delivery. If a certification is a hard requirement for your procurement process, tell us early and we will be honest about whether we can meet it."
      },
      "name": "Do you hold professional indemnity insurance, ISO 27001 or SOC 2?"
    },
    {
      "@type": "Question",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "We reply within four working hours, usually within one. Ongoing support is a monthly retainer with a defined weekly commitment, cancellable without notice. We do not offer an uptime SLA; availability for delivered software is scoped per engagement so we never promise a number we cannot stand behind."
      },
      "name": "What are your service levels and support options?"
    }
  ],
  "speakable": {
    "@type": "SpeakableSpecification",
    "cssSelector": [
      ".faq-question",
      ".faq-answer"
    ]
  }
}
```
