Your Security Is Our Mission. And Our Practice.
We hold ourselves to the same standards we help you achieve. Here
How We Protect Your Data
EU Data Residency
All data stored in EU data centers (Germany). No data leaves the EU.
Encryption at Rest
AES-256 encryption for all stored scan results and user data.
Encryption in Transit
TLS 1.3 for all communications. No exceptions.
Access Controls
Role-based access, 2FA enforcement, and complete audit logging.
Our Compliance Posture
Independently certified by AXE REGISTER
Download our official ISO 9001:2015, ISO/IEC 27001:2022 and ISO/IEC 27017:2015 certificates — issued under IAF mutual recognition.
We can provide a Data Processing Agreement (DPA) on request for all enterprise customers.
Responsible Disclosure
Found a vulnerability? We welcome responsible disclosure. Email [email protected]. We respond within 48 hours and will not take legal action against good-faith researchers.
Report a VulnerabilityInfrastructure & Subprocessors
| Provider | Purpose | Location |
|---|---|---|
| Hetzner | Hosting | Germany |
| DigitalOcean | App Platform | EU (Amsterdam) |
| PostgreSQL | Database | Germany |
| Redis | Queue/Cache | Germany |
Questions About Our Security Practices?
We are happy to discuss our security posture, provide documentation, or arrange a call with our security team.