Loading...

/docs/privacy/security

Security Controls and Incident Response

Version 2026-03-16-v23, updated 2026-03-16.

ControlImplementationScope
Authentication and access protectionSupabase Auth, session management, optional MFA (TOTP), role-based access controlsAccount security and access to product data
Transport and storage securityTLS-protected transport, infrastructure hardening, role-separated accessWeb, API, and backend data processing
Monitoring, abuse detection, and rate limitingSecurity logs, abuse detection, hashed IP-based rate limits, and technical blocking and protection mechanismsAbuse prevention and availability
Authorization and role conceptsNeed-to-know access controls and internal access restrictionsInternal administration and support
Recoverability and resilienceBackup and recovery processes as well as technical redundancy where implementedOperational continuity and incident recovery

Incident Response Facts

  • Detection and initial assessment

    Security-relevant incidents are prioritized, assessed, and technically contained.

  • Containment and recovery

    We apply technical and organizational measures for containment and recovery.

  • Notification duties

    For notifiable breaches, we notify the supervisory authority and, where required, affected persons in line with Art. 33 and 34 GDPR.