Own infrastructure in Europe, ERP connectivity, electronic signature, AI process automation and blockchain timestamping: the technical foundation the portals and processes run on.
What is underneath
The visible part of Kimobox is the portals and the processes. Underneath sits a multi-company low-code platform running on its own infrastructure inside the European Union, with role-based permissions, an audit log of every action, an ERP integration layer, and cross-cutting services — electronic signature, sealing, AI data extraction — that any process can call without additional licences.
Content reviewed on
Model
Multi-company low-codeSeveral entities and sites on one installation, with separated data
Hosting
Own infrastructure in the EUNo international transfers of personal data
Access
Web, iOS and AndroidSame permission model across all three channels
Built-in services
Signature, sealing, AI, document managementCallable from any step of any process
Open interface
REST API and webhooksDescribed with OpenAPI, with scope-based permissions
REST API and intermediate database for integrations
24/7 monitoring and a tested continuity plan
Separate testing and production environments
Own, highly secure servers, never shared with third parties
Real examples
Technical decisions with visible consequences
Group of six entities
One installation or six
Before Six instances of the same software, six upgrades and six sets of users to maintain separately.
After A single multi-company installation with data separated by entity and users who can operate across several where their role allows.
Company with bespoke development
Every process change is a ticket
Before Adding a field to a form means a request to the vendor, a quote and three weeks of waiting.
After The process owner adds it, tests it and publishes it. The vendor gets involved when an integration needs touching, not a form.
Customer security audit
Who did what, and when
Before The previous system logged logins but not actions. Faced with a discrepancy there was no way to reconstruct events.
After An audit log with user, action, object and timestamp, searchable and exportable. The question has a dated answer.
Vocabulary
Architecture, in five terms
Low-code
Building applications through visual configuration rather than programming. Its value is not saving code: it is shortening the distance between whoever knows the process and whoever can change it.
Multi-company
The ability of one installation to run several legal entities with separated data and their own users, sharing configuration where that makes sense.
Audit log
A tamper-evident trail of actions taken in the system. It is a requirement of ISO 27001 and of the Spanish ENS, and the first thing asked for when things get uncomfortable.
Permission role
A set of authorisations assigned to a role rather than a person. It means joiners and leavers do not force a rethink of access one by one.
Cross-cutting service
Functionality available to any process without integrating it again: signing, sealing, extracting data, notifying. It is what avoids buying four tools that do not talk to each other.
Frequently asked questions
What people ask us before getting started
Where is the data hosted?
In our own data centers in the European Union, never on third-party clouds outside the GDPR.
How secure are your servers?
Own, dedicated servers, with encryption in transit and at rest, two-factor authentication and 24/7 monitoring.
How does it connect to my ERP?
Via REST API, file exchange or an intermediate database, depending on what your ERP allows.
What does low-code mean here?
That the application is built by configuring on screen rather than programming. In practice it means whoever knows the process can change it without raising a ticket, and the vendor is only involved when an integration has to be touched.
Can several legal entities run on one installation?
Yes. The model is multi-company: each entity has its own separated data and users, and configuration can be shared where that helps. A group of six entities does not need six installations.
Is there an audit log of actions?
Yes, with user, action, object and timestamp, searchable and exportable. It is a requirement of both ISO 27001 and the Spanish ENS, and the first thing asked for when an event has to be reconstructed.
How are updates handled?
They are deployed centrally, without each customer having to plan a migration. Your own configuration — processes, forms, reports — survives updates because it is data, not code.
Can all the information be exported?
Yes. The data belongs to the customer and can be extracted through the API or by bulk export in open formats, without depending on anyone to release it.
Hand our technical sheet to your IT lead
We'll show you the module running with data similar to yours.
Technology: infrastructure, security, ERP integration and AI
Kimobox's technology layer combines own infrastructure hosted in the European Union, connectivity with your existing ERP, advanced electronic signature under eIDAS, AI-driven process automation and blockchain timestamping of records.
It all runs on our own, highly secure servers, with encryption in transit and at rest, two-factor authentication, continuous monitoring and a GDPR data processing agreement.
We use our own and analytics cookies (Google Analytics) to understand how the site is used. You can accept or reject them. More information