Controls
Each control below is either in place or it isn't listed. There is nothing to score, and nothing held back for a sales conversation.
33 controls across 5 categories.
Infrastructure security
EU data residency maintained
Application data and backups are hosted in EU-based infrastructure regions by default.
Point-in-time backups configured
Databases support point-in-time recovery with a seven-day retention window.
Data encryption at rest utilized
Databases and object storage are encrypted with AES-256.
Encryption in transit enforced
All communication runs over TLS 1.2 or 1.3.
DDoS protection enabled
Traffic is filtered by Cloudflare and Laravel Cloud.
Managed platforms used exclusively
Applications run on managed platforms — there is no unauthorized direct server access.
Infrastructure patching delegated to providers
Infrastructure updates are handled by the managed platform providers.
Per-client environments provisioned
Each client's solution runs in its own server environment, keeping customer data isolated.
Database separation applied to multi-tenant solutions
Where a solution is multi-tenant, it follows database-separation best practices.
Access control
Unique account authentication enforced
Every user has an individual account. Shared logins are not used.
Two-factor authentication required
Mandatory on all systems that handle sensitive data.
Single sign-on prioritized
Access runs through a central identity provider wherever the system supports it.
Access revoked upon termination
Access is withdrawn immediately on role change or offboarding.
Credentials stored in encrypted managers
Secrets are kept in encrypted password managers and environment variables.
Product security
OWASP Top 10 applied
The OWASP Top 10 is used to identify and mitigate risks during development.
Code review conducted
Work is version-controlled in Git and reviewed before it ships.
Automated testing performed continuously
Critical functionality is covered by automated tests that run continuously.
Manual review required for significant changes
Significant changes get manual testing and code review before release.
Development and staging environments separated
Development and staging run separately from production.
External APIs tested in sandbox
Third-party integrations are tested in sandbox environments where the provider offers one.
Third-party dependencies monitored
Third-party modules are monitored and updated under maintenance agreements.
Application and audit logging enabled
Application and audit logs make changes traceable after the fact.
Internal security procedures
Incident response procedures established
Incident management follows a documented process.
Infrastructure monitoring implemented
Downtime, performance, SSL certificates, and third-party disruptions are monitored.
Application monitoring and alerting configured
Crashes and errors raise automatic alerts.
Critical incidents communicated immediately
Affected clients are informed as soon as a critical incident is confirmed, and the root-cause analysis is documented.
Operations log made available
Clients can request the operations log for their solution at any time.
Breach process documented
A written procedure covers isolation, analysis, notification, and improvement.
Data and privacy
Processing limited to agreed purposes
Data is processed strictly per agreement and the purpose for which it was collected.
Production data access minimized
Production data is used only when the case requires it, under controlled conditions.
Data subject rights supported
Rights to insight, correction, and deletion are handled per GDPR.
Data processing agreement signed
A Data Processing Agreement (DPA, "personuppgiftsbiträdesavtal") is signed together with the customer agreement.
Residency scope documented
EU residency covers application data and backups; subprocessor locations are disclosed in full below.