Security

We design for security and privacy by default. Below is an overview of our current practices and standards in scope for certification.

Standards and certifications

  • ISO/IEC 27001: Information Security Management System (ISMS) — in preparation for certification.
  • ISO/IEC 27002: Security controls best practices — used as guidance for controls selection.
  • OWASP ASVS & Top 10 — secure application development and review guidelines.
  • GDPR compliance — data processing agreements, data subject rights, and retention policies.

Platform security

  • Authentication: Email/password with optional 2FA, session management, and device verification.
  • Transport security: HTTPS/TLS for all traffic; HSTS enabled in production.
  • Data protection: Input validation, CSRF protection, rate limiting, and audit logging.
  • File handling: Strict MIME validation and storage via secure object storage.

Operational security

  • Access control: Least privilege and role‑based access for staff.
  • Backups & continuity: Regular backups and tested restoration procedures.
  • Vulnerability management: Dependency monitoring and timely patching.
  • Vendor management: DPAs in place with subprocessors where applicable.

Responsible disclosure

If you believe you have found a security vulnerability, please contact us via our contact page. We will investigate promptly.

Transparantie

We hanteren best practices voor transparantie, zoals het publiceren van subprocessors, SCC/DPA‑informatie en status/uptime. Voorbeeld van een duidelijke EU‑privacy pagina ter inspiratie vind je bij Postmark’s EU Data Protection.

  • Data Processing Agreement (DPA) met SCC’s
  • Overzicht subprocessors + notificaties bij wijzigingen
  • Status/uptime‑overzicht en incidentrapportage

Referentie: Postmark – EU Data Protection