Loading...

/docs/privacy/security

Security Controls and Incident Response

Version 2026-04-04-v24, updated 2026-04-04.

ControlImplementationScope
Authentication and access protectionSupabase Auth, session management, optional MFA (TOTP), role-based access controlsAccount security and access to product data
Transport and storage securityTLS-protected transport, infrastructure hardening, role-separated accessWeb, API, and backend data processing
Monitoring, abuse detection, and rate limitingSecurity logs, abuse detection, hashed IP-based rate limits, and technical blocking and protection mechanismsAbuse prevention and availability
Authorization and role conceptsNeed-to-know access controls and internal access restrictionsInternal administration and support
Recoverability and resilienceBackup and recovery processes as well as technical redundancy where implementedOperational continuity and incident recovery

Incident Response Facts

  • Detection and initial assessment

    Security-relevant incidents are prioritized, assessed, and technically contained.

  • Containment and recovery

    We apply technical and organizational measures for containment and recovery.

  • Notification duties

    For notifiable breaches, we notify the supervisory authority and, where required, affected persons in line with Art. 33 and 34 GDPR.

Cookie consent

We always use necessary cookies and technically required storage access. Optional analytics are used only with your consent.