Skip to contentv0.1.0
PIMgate
01 · Security & sovereignty

Your data stays in the EU and Switzerland.

Product data includes prices, customer agreements and products that are not yet announced. PIM Gate is operated by a Swiss company, hosted in Germany by default, and built so that each customer's data is isolated, every access is entitled and every relevant action is logged. This page lists what is in place today, what ships in 2026 and what is on the roadmap — nothing more.

PIM GATE · SECURITY FACT SHEET

HOSTING
DE · HETZNER FALKENSTEINDEFAULT
SWISS HOSTING
CH DATA CENTREON REQUEST
DEDICATED / ON-PREM
ENTERPRISEON REQUEST
ISOLATION
TENANT · DATA LEVEL
AUDIT
APPEND-ONLY LOG
BACKUPS
DAILY SNAPSHOTS · OFF-HOST
DATABASE
POSTGRESQL
PRIVACY
GDPR · revDSG · DPA
AI
YOUR MODEL · YOUR PROVIDER
SSO · SCIM · MFA
—

EU / CH hostingGDPRrevDSGTenant isolationAppend-only audit

01 · Data residency

Germany by default. Switzerland or your own infrastructure on request.

One codebase runs in three ways. The choice depends on your data-residency and regulatory requirements, not on which features you get.

Deployment optionsThree ways to run the same codebase: multi-tenant SaaS in Germany, hosting in a Swiss data centre, and a dedicated or on-premises deployment — same releases in each.One codebaseSame features, same API, same upgrade pathNo forked productEU / DESaaS multi-tenantShared platform, isolated tenantsManaged updates and backupsFastest to startStandardCHSwiss hostingData stays in SwitzerlandSame platform, separate regionContractual data residencyOn requestYour infrastructureDedicated / on-premSingle-tenant or in your data centreYour network, your policiesEnterprise agreementOn requestMove between options without rebuilding integrations
Deployment options at a glance

SaaS, hosted in Germany

PIM Gate runs as a multi-tenant platform at Hetzner in Falkenstein, Germany. We operate, update and back up the platform; your team configures portals, rights and rules. This is the default for all versions.

Swiss hosting

For companies whose data must remain in Switzerland, the platform can be hosted in a Swiss data centre. Available on request.

Dedicated or on-prem

For regulated industries such as medtech, insurance or public institutions, PIM Gate can run as a dedicated deployment or be installed in your own infrastructure. Available on request under an enterprise agreement.

OptionLocationOperated byAvailability
SaaS multi-tenantGermany (Hetzner, Falkenstein)Netgen SwitzerlandDEFAULT
Swiss hostingSwiss data centreNetgen SwitzerlandON REQUEST
Dedicated / on-premagreed per contractagreed per contractON REQUEST
02 · 03 · Tenant isolation

Your tenant is yours alone.

A tenant is an isolated space on the platform with its own data, users, configuration, API tokens and subdomain. Isolation is enforced at data level, not only in the user interface.Every request carries a tenant scope. Data, users, portals and API tokens of one tenant are not visible to another. Groups with several brands or country companies can run one branded tenant per brand, each with its own users and domain, so that isolation follows the organisation. For testing, a separate stage/test tenant keeps experiments away from production data and users.

  • Tenant isolation at data level
  • Per-tenant API tokens
  • Tenant subdomains and custom domains with certificate per tenant2026
  • Separate stage/test tenant, bookable with a production subscription
Tenant and portal treeA PIM Gate tenant with its own domain, holding a customer, sales, supplier and media portal, each on its own address and drawing from one governed catalog.SaaS platform · EU / DEPIM GateShared codebase · isolated tenants · row-level isolationTenant · MESSARAmessara.pimgate.aiOwn users · own data · own brandingmessara-de.pimgate.aiBrand tenant · DEmessara-ch.pimgate.aiBrand tenant · CHPortals · selected by pathCustomer portalmessara.pimgate.ai/p/customerCatalog viewscollectionsshare linksSales portalmessara.pimgate.ai/p/salesCustomer scopeagreementsactivitySupplier portalmessara.pimgate.ai/p/supplierSubmissionsvalidationre-submitMedia portalmessara.pimgate.ai/p/mediaBriefsversionsapprovalsOne tenant per brand or country · no per-portal DNS or certificate

03 · Access control

Every route, query and asset checked against explicit rights.

Entitlements decide what each user, portal and API token may see and do. They are enforced on the server for every page, export and API response — a filtered view is never just hidden in the browser.

messara.pimgate.ai / admin / rolesAdmin
Roles & scopes
Rolecatalog.readassets.downloadprices.viewsubmit.datausers.manage
Tenant admin
Sales rep··
Customer···
Agency···
Supplier····

Example — configurable per tenant

Audit logAppend-only
  • 2026-09-24 14:32:10 · user:j.meier · download · 24 assets · portal:sales
  • 2026-09-24 14:28:52 · user:j.meier · login · mfa:totp · portal:sales
  • 2026-09-24 11:07:03 · user:svc.supplier · submit · 148 rows · portal:supplier
  • 2026-09-24 09:41:19 · user:a.keller · approve · translation en-GB · 12 segments · module:translation
  • 2026-09-23 17:12:44 · user:admin · role.grant · sales_rep → m.oertli · tenant:messara
  • 2026-09-23 16:55:01 · user:k.brenner · share.create · expires 2026-10-06 · portal:customer
Retention 365 dExport CSV · JSON6 of 18'204

EXAMPLE — CONFIGURABLE PER TENANT

Entitlement layersAccess narrowed layer by layer — tenant, portal, role, market, category, asset scope — until a user sees only the records they are entitled to.Signed-in userj.meier · Sales rep · CHTenantMESSARA20,418 SKUsPortal/p/sales14,902 SKUsRoleSales rep6,140 SKUsMarketCH2,208 SKUsCatalog viewAgreement 2026-B514 SKUsAsset scopeApproved media only312 SKUsThis user sees312of 20,418 SKUsEnforced server-sideEvery layer is a deny-by-default filter · nothing leaks between tenants

What is in place, what comes next

  • Entitlements per tenant, portal, role, market and category, down to the single asset
  • Server-side entitlement filtering on every API response
  • Versioned REST API with per-tenant tokens and rate limiting
  • Signed webhooks
  • Roles and groups, admin console2026
  • Share links with expiry date and download cap2026
  • Single sign-on (OIDC, SAML), SCIM provisioning, multi-factor authenticationROADMAP

We list SSO, SCIM and MFA as roadmap items because they are. If your rollout depends on them, tell us in the first call — we will show you the current plan.

04 · 05 · Audit

Every relevant action leaves a trace that cannot be edited.

Invitations, approvals, downloads, role changes and exports are written to an append-only log. Together with versioned exports, it answers who had which data, and when.In regulated industries, the question is rarely whether data was shared, but which version, with whom and when. PIM Gate stores every export as a version and every relevant user action as an entry that cannot be changed afterwards. That turns an audit request into a query.

  • Append-only audit log
  • Versioned exports, any two versions comparable side by side
  • Audit log UI in the admin console2026
  • Bulk downloads with audit trail2026
  • Audit-log retention of 10 years, as an add-on

DEMO DATA · FICTIONAL USERS

messara.pimgate.ai / admin / rolesAdmin
Roles & scopes
Rolecatalog.readassets.downloadprices.viewsubmit.datausers.manage
Tenant admin
Sales rep··
Customer···
Agency···
Supplier····

Example — configurable per tenant

Audit logAppend-only
  • 2026-09-24 14:32:10 · user:j.meier · download · 24 assets · portal:sales
  • 2026-09-24 14:28:52 · user:j.meier · login · mfa:totp · portal:sales
  • 2026-09-24 11:07:03 · user:svc.supplier · submit · 148 rows · portal:supplier
  • 2026-09-24 09:41:19 · user:a.keller · approve · translation en-GB · 12 segments · module:translation
  • 2026-09-23 17:12:44 · user:admin · role.grant · sales_rep → m.oertli · tenant:messara
  • 2026-09-23 16:55:01 · user:k.brenner · share.create · expires 2026-10-06 · portal:customer
Retention 365 dExport CSV · JSON6 of 18'204

05 · Operations

We run it. You configure it.

PIM Gate is SaaS. Operation, updates and backups are our job, so your team works on portals, rights and rules instead of servers.

DATABASE

PostgreSQL.

SNAPSHOTS

Daily snapshots of the platform data.

OFF-HOST

Backups stored off-host, separate from the running system.

UPDATES

Platform updates rolled out by us; no installation work on your side.

Service levels

  • Versions S and M · business-hours support (S: EU; M: priority, EU + EN) · Premium SLA available as an add-on
  • Versions L and XL · 99.9% availability SLA · XL includes a customer success manager

06 · Privacy

GDPR and Swiss revDSG, by design.

PIM Gate is designed for the EU General Data Protection Regulation and the revised Swiss Federal Act on Data Protection. A data processing agreement is available for every customer.

Most of what flows through PIM Gate is product data. Personal data appears where people use the platform: portal users, admins, suppliers and the audit log that records their actions. As a customer, you remain the controller of that data; Netgen Switzerland processes it on your behalf under a data processing agreement. Hosting in Germany by default and in Switzerland on request keeps the data in jurisdictions covered by both laws.

  • Data processing agreement (DPA)AVAILABLERequest
  • List of subprocessorsON REQUESTRequest
  • Technical and organisational measuresON REQUESTRequest
Data processing agreement (DPA)
07 · 08 · AI and your data

You choose the model. You choose the provider.

PIM Gate does not bind you to one AI vendor. For each language or market you decide which engine is used — or whether any is used at all.

Translation engine choiceChanged segments routed to the engine configured for that language or market, held in a review queue, and only then published — with a parallel human-translator path.Source attributedescriptionde-DE · MS-12011Delta detectorNew / changed segmentsTM lookupTMX · exact & fuzzyTerminology checkTBX termbaseMT / LLM engineDeepL · OpenAI · AnthropicReview queueOne reviewer per languageTM match 71% · new 29%Per language · EU hosting selectableApprovePublish to channelsPortals · shop · feedsWrite back to sourceAs a draft language versionExternal translatorXLIFF / XLSX package out · re-import inRe-import lands back in the review queueOnly new or changed segments are ever sent to an engine

Your choice of model and provider.

Connect OpenAI, Anthropic, DeepL, Azure OpenAI or EU and local models, per language or market. Which provider's terms apply to your data is a decision you make, not one we make for you.

EU and local options.

Where data should not leave the EU or your own infrastructure, choose an EU-hosted or local model for that language or market.

A proposal, never a publication.

Machine translation is a suggestion. Nothing is published without the review step you configure. You can also run translation entirely with human translators via export and import packages.

2026ROADMAP

08 · Reviews and disclosure

Ask us anything. Tell us anything.

Security reviews

Your IT and procurement teams will have their own questions and questionnaires. Send them to us. We walk your architects through the platform, the hosting setup and the entitlement model, and answer in writing where your process requires it. If your process requires specific certifications or attestations, ask us about the current status.

Request a security review call

Responsible disclosure

If you believe you have found a security vulnerability in PIM Gate or on pimgate.ai, please report it to us privately so we can investigate and fix it before it is disclosed. Include a description, the affected URL or component, steps to reproduce and your contact details. Please do not access or modify data that is not yours, and do not run tests that degrade the service for others.

security@pimgate.ai

09 · Questions

Questions from IT and data protection.

In Germany (EU) by default, at Hetzner in Falkenstein. Swiss hosting is available on request; dedicated or on-prem deployments on request under an enterprise agreement.

Put a gate between your catalog and chaos.