Public infrastructure map · version 1.0

European location. Visible dependencies.

Digital sovereignty is more than a server address. This page states where Cindra runs, which providers can influence the service and which dependencies still prevent a claim of complete sovereignty.

Verified 12 August 2026

What runs where

These are the current production paths, not future intentions. A European data region is reported separately from the legal control of its provider.

Netherlands

Public website and files

The public site, app shell, styles, images, fonts and browser libraries are served from Cindra’s TransIP web hosting in the Netherlands. Cindra’s authoritative DNS also uses TransIP nameservers.

Frankfurt region

Accounts and application data

Cindra’s managed Supabase project is active in the exact AWS region eu-central-1 in Frankfurt. The project’s primary Postgres database and Auth service use that regional deployment.

Non-EU control

Platform and email dependencies

Supabase’s current contracting entity is in Singapore and its hosted Frankfurt region runs on AWS. Domain email is routed through Google Workspace. These dependencies are disclosed, not relabelled as European ownership.

What this does—and does not—mean

Data location is concrete

The public files are in the Netherlands and the configured application-data region is Frankfurt. Supabase documents that a project’s database, Auth and Storage are pinned to its selected primary region.

Location is not full sovereignty

A non-EU provider, its underlying cloud provider, logs, backups, support access, email processing and legal contracts can affect control and international-transfer analysis. “EU region” is not presented as “EU-owned”.

Compliance remains shared work

Supabase explicitly describes GDPR compliance as a shared responsibility. Cindra must still publish its responsible legal entity, purposes, retention choices, processors and member rights before calling its legal transparency complete.

Governance is a separate control layer

Cindra remains founder-led. Hosting choices do not create member ownership, a cooperative, a member veto or independent stewardship. Those limits are stated on the governance page.

Member-facing data paths

Signed-out visit
The registration entrance loads its first-party files from TransIP and stays idle: it does not read the member directory or poll the feed without a member session.
Account access
Registration, confirmation, sign-in, sessions and recovery use Supabase Auth. Real confirmation and recovery inbox delivery is not yet claimed as proven.
Goals and profiles
Application data is stored through the regional Supabase project. New goals start private; only an explicit public choice creates a public goal.
Private collaboration
Private goal context and messages are not rendered on public acquisition pages. A private invitation reveals context only after sign-in and a valid, unused invitation.
Email
cindra.eu mail records point to Google Workspace. This page does not claim that mailbox data or every authentication-mail path is EU-only.
Exit
Signed-in members can export their Cindra data locally and request self-service account deletion. These controls do not remove provider-level legal obligations.

Controls in place today

Cindra reduces unnecessary data movement while being explicit about what remains outside direct control.

No attention analytics

The public release contains no Google Analytics, Tag Manager, tracking pixel or third-party font request. Cindra does not record viewing time, opens or clicks as an engagement score.

First-party release assets

The Supabase browser library, Font Awesome files, fonts, images, styles and application code are served from Cindra’s own public host rather than fetched from a runtime CDN.

Explicit public boundaries

Anonymous goal previews return only fields from a goal its owner explicitly marked public. Missing, malformed and legacy visibility values are treated as private.

Security contact

Cindra publishes a standard security.txt contact in English and Dutch. It contains no vulnerability details or member data.

Work that is not finished

Cindra is not presented as fully sovereign or legally complete today. The responsible legal entity, public privacy notice, DPA position, complete subprocessor list, retention schedule and verified authentication-mail delivery remain unpublished or unproven. Reducing non-EU platform and email dependency is a future architecture and governance decision, not a promise with an invented deadline.

Verification sources

Project configuration was checked directly on 12 August 2026. Provider statements can change; the links below are the current primary references.

Change history

First public map of production hosting, application-data region, email routing, non-EU provider control, current safeguards and unresolved sovereignty work.