Security

Our security protocols.

These are the topics that come up in procurement questionnaires and security reviews, collected in one place.

01

Access management

  • —Role-based permissions and least privilege
  • —Two-factor authentication on admin panels
  • —Access for departing staff is revoked the same day
02

Data protection

  • —TLS in transit, encrypted disks at rest
  • —Masking and defined retention for personal data
  • —No real customer data in test environments
03

Application security

  • —Input validation and output sanitisation
  • —API token checks and request rate limits
  • —Dependency scanning and regular updates
04

Monitoring and logging

  • —Audit log showing who changed what
  • —Immediate alerts on critical failures
  • —Log access restricted by permission
05

Incident response

  • —Fast diagnosis through the correlation code on each response
  • —Impact assessment and written notification
  • —Personal data breaches reported within the statutory window
06

Compliance

  • —GDPR and KVKK processes
  • —Aligned with the ISO 27001 / 27701 frameworks
  • —A data processing agreement (DPA) is signed

We make no certification claims. We work against the ISO 27001 and ISO 27701 frameworks; when we hold an audited certificate, it will be stated on this page.