Contact security

Controls

Each control below is either in place or it isn't listed. There is nothing to score, and nothing held back for a sales conversation.

33 controls across 5 categories.

Infrastructure security

  • EU data residency maintained

    Application data and backups are hosted in EU-based infrastructure regions by default.

  • Point-in-time backups configured

    Databases support point-in-time recovery with a seven-day retention window.

  • Data encryption at rest utilized

    Databases and object storage are encrypted with AES-256.

  • Encryption in transit enforced

    All communication runs over TLS 1.2 or 1.3.

  • DDoS protection enabled

    Traffic is filtered by Cloudflare and Laravel Cloud.

  • Managed platforms used exclusively

    Applications run on managed platforms — there is no unauthorized direct server access.

  • Infrastructure patching delegated to providers

    Infrastructure updates are handled by the managed platform providers.

  • Per-client environments provisioned

    Each client's solution runs in its own server environment, keeping customer data isolated.

  • Database separation applied to multi-tenant solutions

    Where a solution is multi-tenant, it follows database-separation best practices.

Access control

  • Unique account authentication enforced

    Every user has an individual account. Shared logins are not used.

  • Two-factor authentication required

    Mandatory on all systems that handle sensitive data.

  • Single sign-on prioritized

    Access runs through a central identity provider wherever the system supports it.

  • Access revoked upon termination

    Access is withdrawn immediately on role change or offboarding.

  • Credentials stored in encrypted managers

    Secrets are kept in encrypted password managers and environment variables.

Product security

  • OWASP Top 10 applied

    The OWASP Top 10 is used to identify and mitigate risks during development.

  • Code review conducted

    Work is version-controlled in Git and reviewed before it ships.

  • Automated testing performed continuously

    Critical functionality is covered by automated tests that run continuously.

  • Manual review required for significant changes

    Significant changes get manual testing and code review before release.

  • Development and staging environments separated

    Development and staging run separately from production.

  • External APIs tested in sandbox

    Third-party integrations are tested in sandbox environments where the provider offers one.

  • Third-party dependencies monitored

    Third-party modules are monitored and updated under maintenance agreements.

  • Application and audit logging enabled

    Application and audit logs make changes traceable after the fact.

Internal security procedures

  • Incident response procedures established

    Incident management follows a documented process.

  • Infrastructure monitoring implemented

    Downtime, performance, SSL certificates, and third-party disruptions are monitored.

  • Application monitoring and alerting configured

    Crashes and errors raise automatic alerts.

  • Critical incidents communicated immediately

    Affected clients are informed as soon as a critical incident is confirmed, and the root-cause analysis is documented.

  • Operations log made available

    Clients can request the operations log for their solution at any time.

  • Breach process documented

    A written procedure covers isolation, analysis, notification, and improvement.

Data and privacy

  • Processing limited to agreed purposes

    Data is processed strictly per agreement and the purpose for which it was collected.

  • Production data access minimized

    Production data is used only when the case requires it, under controlled conditions.

  • Data subject rights supported

    Rights to insight, correction, and deletion are handled per GDPR.

  • Data processing agreement signed

    A Data Processing Agreement (DPA, "personuppgiftsbiträdesavtal") is signed together with the customer agreement.

  • Residency scope documented

    EU residency covers application data and backups; subprocessor locations are disclosed in full below.