1. Where we stand today
We are a small European engineering team and we describe our security posture literally, without borrowing credibility we have not earned.
We do not hold a SOC 2, ISO 27001 or equivalent third-party attestation, and we do not claim one. We have not commissioned an audit, so there is no report, bridge letter or certification to share. If that changes we will say so here with the actual scope and date.
What we can give a reviewer is this page, the DPA, the sub-processor list, the retention schedule and a direct line to the people who run the systems.
2. Infrastructure and hosting
The platform runs on managed cloud infrastructure with primary data storage in the European Union. Production is segregated from development and test environments, and no production personal data is used for development or testing.
Availability is supported by automated monitoring and encrypted backups on a rolling 35-day cycle. Restore procedures are exercised periodically.
3. Encryption
Data in transit is protected with TLS 1.2 or higher on all public endpoints. Data at rest, including databases, object storage and backups, is encrypted using AES-256 or the provider-managed equivalent.
Secrets and API credentials for connected platforms are stored encrypted and are never written to application logs.
4. Access control
Access to production systems follows least privilege and is limited to personnel who need it for their role. Administrative access requires individual accounts and multi-factor authentication.
Access rights are reviewed periodically and revoked promptly when a role changes or an engagement ends. Customer data is accessed only to operate the service, to resolve a support request, or where the customer instructs us.
5. Logging and monitoring
Security-relevant events, administrative actions and authentication activity are logged and retained for 12 months. Logs are monitored for anomalies and are used for incident investigation and accountability under Article 32 GDPR.
6. Secure development and vulnerability management
Changes go through peer review before reaching production. Dependencies are monitored for published vulnerabilities and patched on a risk-based schedule: critical issues are addressed as a priority, other issues in the normal release cycle.
We do not currently run a paid bug-bounty programme. Reports from independent researchers are welcome and handled under section 7.
7. Security contact and reporting a vulnerability
Report a suspected vulnerability or security incident to [email protected] with SECURITY in the subject line. Include what you found, how to reproduce it, and the impact you believe it has.
We acknowledge security reports within 2 business days, give an initial assessment within 5 business days, and keep the reporter updated until the issue is closed.
If you are testing in good faith, please do not access, modify or delete data that is not yours, do not degrade the service, and do not disclose the issue publicly before we have had a reasonable chance to fix it. We will not pursue researchers who follow these principles.
8. Incident response and breach notification
Suspected incidents are triaged, contained and investigated, and remediation is tracked to closure. We record what happened, what data was involved and what we changed as a result.
Where we act as processor and become aware of a personal data breach, we notify the affected customer without undue delay and within 48 hours, with the information they need to meet their own Article 33 obligations. Where we act as controller we notify the Garante per la protezione dei dati personali within 72 hours where the breach is likely to result in a risk to individuals, and inform affected individuals where the risk is high.
9. Vendor and sub-processor management
Vendors that may process personal data are assessed before engagement and bound by written data-protection terms. The current list is published on the sub-processor page, with locations and transfer safeguards.
10. What we need from you
Security is shared. Use strong, unique credentials and enable multi-factor authentication, keep your user list current and remove people who leave, grant integrations only the scopes they need, and configure the agent so it cannot take consequential actions without the guardrails you want.