Our security protocols.
These are the topics that come up in procurement questionnaires and security reviews, collected in one place.
01
Access management
- —Role-based permissions and least privilege
- —Two-factor authentication on admin panels
- —Access for departing staff is revoked the same day
02
Data protection
- —TLS in transit, encrypted disks at rest
- —Masking and defined retention for personal data
- —No real customer data in test environments
03
Application security
- —Input validation and output sanitisation
- —API token checks and request rate limits
- —Dependency scanning and regular updates
04
Monitoring and logging
- —Audit log showing who changed what
- —Immediate alerts on critical failures
- —Log access restricted by permission
05
Incident response
- —Fast diagnosis through the correlation code on each response
- —Impact assessment and written notification
- —Personal data breaches reported within the statutory window
06
Compliance
- —GDPR and KVKK processes
- —Aligned with the ISO 27001 / 27701 frameworks
- —A data processing agreement (DPA) is signed
We make no certification claims. We work against the ISO 27001 and ISO 27701 frameworks; when we hold an audited certificate, it will be stated on this page.