Security at ProWiki

How we protect your wiki and its data.

  • Single-tenant infrastructure Your wiki runs on its own server, with no other customers on the machine.
  • Hosted in Germany ISO 27001-certified data centers in Germany, offsite backups in France, and no US-based service in the data path unless you opt in to Cloudflare. Other regions on request.
  • Encryption TLS 1.2 and 1.3 with HSTS in transit. Full-disk and memory encryption (LUKS, AMD SEV-SNP) on request.
  • Backups and recovery Daily server snapshots plus daily encrypted offsite backups, kept for 8 days, 6 weeks and 6 months on append-only storage. Disaster recovery is tested quarterly.
  • Monitoring and patching 24/7 monitoring with automated alerting, security updates applied promptly, and infrastructure managed as code with peer review.
  • Access controls Server access only with a hardware key from our private network, logged, limited to three engineers and reviewed quarterly.
  • Your users Two-factor authentication (MFA / 2FA) and role-based permissions on every wiki. Single Sign-On (SSO) via OpenID Connect as an add-on.
  • Data export Your data in open formats at any time, and a full export when you leave.
  • Spam protection Built-in spam prevention helps keep even public and open wikis clean.

GDPR and compliance

We are committed to compliance with the EU General Data Protection Regulation (GDPR) and have implemented a wide range of organisational and technical measures.

ProWiki wikis are hosted and processed in Germany by default. A Data Processing Agreement (DPA) and documentation of our technical and organizational measures (TOMs) are available on request. Contact us to learn more.

Hosting is governed by the Customer Agreement, Service Level Agreement, Acceptable Use Policy and Usage Limits. The Service Level Agreement commits to 99.9% availability.

GDPR logo

The full picture

Data centers, sub-processors, backup locations and access controls are described in full under security and data protection on professional.wiki.

MediaWiki Security

Security is taken seriously by the MediaWiki developers, as MediaWiki powers Wikipedia, one of the world's most popular websites. Steps are taken to prevent common attack vectors such as XSS and CSRF. SQL injection and RCE are unheard of in MediaWiki. As the world's most popular Open Source wiki software, MediaWiki has many eyes on it, and security issues are quickly fixed.

Use the wiki admin panel to configure user permissions, authentication settings including two-factor authentication (MFA / 2FA), Single Sign-On (SSO), approval settings, and more. ProWiki comes with many MediaWiki extensions focused on the security requirements of the typical organization.

Accountability and Traceability

MediaWiki comes with full version history. Every edit is logged and can be traced back to the user who made it. You can compare versions and see who changed what and when. You can roll back changes and even restore deleted content.

MediaWiki gives you many options to keep track of what is going on in your wiki. You can subscribe to change notifications for specific pages, see what changes a specific user made, or watch the global change log ("Recent Changes"). Use advanced filtering options to only see changes that are relevant to you. Example: file uploads by new users.

For increased transparency, users can leave edit summaries to explain their changes or discuss changed on "Talk pages".

Request your wiki today

Set up by MediaWiki experts, typically ready within 2 business days.

Request your wiki