Security & Trust

Your Security Is Our Mission. And Our Practice.

We hold ourselves to the same standards we help you achieve. Here

How We Protect Your Data

EU Data Residency

All data stored in EU data centers (Germany). No data leaves the EU.

Encryption at Rest

AES-256 encryption for all stored scan results and user data.

Encryption in Transit

TLS 1.3 for all communications. No exceptions.

Access Controls

Role-based access, 2FA enforcement, and complete audit logging.

Our Compliance Posture

Independently certified by AXE REGISTER

Download our official ISO 9001:2015, ISO/IEC 27001:2022 and ISO/IEC 27017:2015 certificates — issued under IAF mutual recognition.

We can provide a Data Processing Agreement (DPA) on request for all enterprise customers.

Responsible Disclosure

Found a vulnerability? We welcome responsible disclosure. Email [email protected]. We respond within 48 hours and will not take legal action against good-faith researchers.

Report a Vulnerability

Infrastructure & Subprocessors

ProviderPurposeLocation
HetznerHostingGermany
DigitalOceanApp PlatformEU (Amsterdam)
PostgreSQLDatabaseGermany
RedisQueue/CacheGermany

Questions About Our Security Practices?

We are happy to discuss our security posture, provide documentation, or arrange a call with our security team.