Security & Trust

You’re trusting us with your security data. Here’s how we protect it.

SekuRad holds sensitive operational data — incidents, sites, personnel, movements. We build for that responsibility from the database up. This page summarises our posture; for the contractual detail see our DPA and Privacy Policy.

Tenant isolation at the database

Every customer's data is isolated with PostgreSQL row-level security — enforced in the database, not just application code. One customer can never read another's data, even in the event of an app-layer bug.

Encryption everywhere

All traffic is encrypted in transit with TLS. Data is encrypted at rest by our infrastructure providers. Secrets are held in managed, access-controlled stores.

Authentication & access control

Sign-in is handled by a dedicated identity provider with multi-factor authentication support. In-app access is scoped by role down to region, country, and site. Enterprise SSO/SAML is on our roadmap (coming soon).

Audit logging

Security-relevant actions are written to an append-only audit trail — who did what, when — for accountability, forensics, and compliance evidence.

EU-region hosting

The application is hosted in Germany (Hetzner) and the database runs in Frankfurt (Supabase), on audited EU infrastructure (ISO 27001 / SOC 2 providers), with managed backups and point-in-time recovery.

Least privilege & separation

Internal access follows least-privilege principles, background jobs run with scoped system context, and platform administration is separated from tenant data by design.

Operational assurance

Commitments backed by documented processes and rehearsals — not just intentions.

Tested backup & recovery

Recovery objectives: RTO 4 hours, RPO 24 hours. The restore path is rehearsed — most recently July 2026, with every table verified row-exact against production — and re-tested quarterly.

Incident response with a clock

A documented incident-response process sits behind our contractual commitment: affected customers are notified within 72 hours of us becoming aware of a personal-data breach.

DPIA support pack

Running a Data Protection Impact Assessment (GDPR Art. 35 / PDPL)? We provide a support pack with the processor-side facts — data flows, high-risk analysis, and measures. Request it via privacy@sekurad.com.

Your data stays yours

Full self-service export (JSON) at any time, plus a tamper-evident audit-log export. On termination, data is returned or deleted within 30 days.

Sub-processors

The vetted providers we rely on, each bound by data-protection terms.

ProviderPurposeLocation
Hetzner Online GmbHApplication hosting & deliveryGermany (EU)
Supabase (PostgreSQL)Primary database & file storageEU
Clerk Inc.Authentication & identityUSA (SCCs)
OpenAIAI assistant (Keva) — features you opt intoUSA (SCCs, no training on your data)
AnthropicAI assistant (Keva) — features you opt intoUSA (SCCs, no training on your data)
ResendTransactional & alert emailUSA (SCCs)
LemonSqueezyBilling & payment processingUSA (SCCs)
Sentry (Functional Software, Inc.)Error & performance monitoring (PII disabled)USA (SCCs)

Report a vulnerability

Found a security issue? We want to hear from you. Email security@sekurad.com with details and steps to reproduce. We investigate every report and will not pursue good-faith research.

Working toward formal certification (SOC 2 / ISO 27001) — current controls above. Questions from your security team? Reach us at security@sekurad.com.