Our own servers in Europe · GDPR · Support in your language

Technology

The technology behind everything else

Own infrastructure in Europe, ERP connectivity, electronic signature, AI process automation and blockchain timestamping: the technical foundation the portals and processes run on.

What is underneath

The visible part of Kimobox is the portals and the processes. Underneath sits a multi-company low-code platform running on its own infrastructure inside the European Union, with role-based permissions, an audit log of every action, an ERP integration layer, and cross-cutting services — electronic signature, sealing, AI data extraction — that any process can call without additional licences.

Content reviewed on

Model
Multi-company low-code Several entities and sites on one installation, with separated data
Hosting
Own infrastructure in the EU No international transfers of personal data
Access
Web, iOS and Android Same permission model across all three channels
Built-in services
Signature, sealing, AI, document management Callable from any step of any process
Open interface
REST API and webhooks Described with OpenAPI, with scope-based permissions

Also included


The technical pieces the platform runs on

  • Advanced electronic signature under eIDAS
  • Blockchain timestamping as proof of integrity
  • REST API and intermediate database for integrations
  • 24/7 monitoring and a tested continuity plan
  • Separate testing and production environments
  • Own, highly secure servers, never shared with third parties
PORTALS AND PROCESSES Employees · Customers · Suppliers · Contractors KIMOBOX CORE Data, permissions and flows, in one place INFRASTRUCTURE EU servers SECURITY GDPR · encryption CONNECTIVITY ERP · open API THE TECHNICAL FOUNDATION EVERYTHING ELSE RESTS ON

Real examples


Technical decisions with visible consequences

Group of six entities

One installation or six

Before Six instances of the same software, six upgrades and six sets of users to maintain separately.

After A single multi-company installation with data separated by entity and users who can operate across several where their role allows.

Company with bespoke development

Every process change is a ticket

Before Adding a field to a form means a request to the vendor, a quote and three weeks of waiting.

After The process owner adds it, tests it and publishes it. The vendor gets involved when an integration needs touching, not a form.

Customer security audit

Who did what, and when

Before The previous system logged logins but not actions. Faced with a discrepancy there was no way to reconstruct events.

After An audit log with user, action, object and timestamp, searchable and exportable. The question has a dated answer.

Vocabulary


Architecture, in five terms

Low-code
Building applications through visual configuration rather than programming. Its value is not saving code: it is shortening the distance between whoever knows the process and whoever can change it.
Multi-company
The ability of one installation to run several legal entities with separated data and their own users, sharing configuration where that makes sense.
Audit log
A tamper-evident trail of actions taken in the system. It is a requirement of ISO 27001 and of the Spanish ENS, and the first thing asked for when things get uncomfortable.
Permission role
A set of authorisations assigned to a role rather than a person. It means joiners and leavers do not force a rethink of access one by one.
Cross-cutting service
Functionality available to any process without integrating it again: signing, sealing, extracting data, notifying. It is what avoids buying four tools that do not talk to each other.

Frequently asked questions


What people ask us before getting started

Where is the data hosted?

In our own data centers in the European Union, never on third-party clouds outside the GDPR.

How secure are your servers?

Own, dedicated servers, with encryption in transit and at rest, two-factor authentication and 24/7 monitoring.

How does it connect to my ERP?

Via REST API, file exchange or an intermediate database, depending on what your ERP allows.

What does low-code mean here?

That the application is built by configuring on screen rather than programming. In practice it means whoever knows the process can change it without raising a ticket, and the vendor is only involved when an integration has to be touched.

Can several legal entities run on one installation?

Yes. The model is multi-company: each entity has its own separated data and users, and configuration can be shared where that helps. A group of six entities does not need six installations.

Is there an audit log of actions?

Yes, with user, action, object and timestamp, searchable and exportable. It is a requirement of both ISO 27001 and the Spanish ENS, and the first thing asked for when an event has to be reconstructed.

How are updates handled?

They are deployed centrally, without each customer having to plan a migration. Your own configuration — processes, forms, reports — survives updates because it is data, not code.

Can all the information be exported?

Yes. The data belongs to the customer and can be extracted through the API or by bulk export in open formats, without depending on anyone to release it.

Hand our technical sheet to your IT lead

We'll show you the module running with data similar to yours.

Request a demo

Sources


Where each figure comes from

References to the official text in force. If a standard is revised, this page is updated and the review date says so.

  1. ISO/IEC 27001:2022 — Information security management systems ISO/IEC · 25 October 2022
  2. Royal Decree 311/2022, Spanish National Security Framework BOE-A-2022-7191 · 4 May 2022
  3. Regulation (EU) 2016/679 (GDPR), art. 32: security of processing EUR-Lex · Applicable since 25 May 2018

Technology: infrastructure, security, ERP integration and AI

Kimobox's technology layer combines own infrastructure hosted in the European Union, connectivity with your existing ERP, advanced electronic signature under eIDAS, AI-driven process automation and blockchain timestamping of records.

It all runs on our own, highly secure servers, with encryption in transit and at rest, two-factor authentication, continuous monitoring and a GDPR data processing agreement.