Security

Our security protocols.

These are the topics that come up in procurement questionnaires and security reviews, collected in one place.

01

Access management

  • Role-based permissions and least privilege
  • Two-factor authentication on admin panels
  • Access for departing staff is revoked the same day
02

Data protection

  • TLS in transit, encrypted disks at rest
  • Masking and defined retention for personal data
  • No real customer data in test environments
03

Application security

  • Input validation and output sanitisation
  • API token checks and request rate limits
  • Dependency scanning and regular updates
04

Monitoring and logging

  • Audit log showing who changed what
  • Immediate alerts on critical failures
  • Log access restricted by permission
05

Incident response

  • Fast diagnosis through the correlation code on each response
  • Impact assessment and written notification
  • Personal data breaches reported within the statutory window
06

Compliance

  • GDPR and KVKK processes
  • Aligned with the ISO 27001 / 27701 frameworks
  • A data processing agreement (DPA) is signed

We make no certification claims. We work against the ISO 27001 and ISO 27701 frameworks; when we hold an audited certificate, it will be stated on this page.