SekuRad holds sensitive operational data — incidents, sites, personnel, movements. We build for that responsibility from the database up. This page summarises our posture; for the contractual detail see our DPA and Privacy Policy.
Every customer's data is isolated with PostgreSQL row-level security — enforced in the database, not just application code. One customer can never read another's data, even in the event of an app-layer bug.
All traffic is encrypted in transit with TLS. Data is encrypted at rest by our infrastructure providers. Secrets are held in managed, access-controlled stores.
Sign-in is handled by a dedicated identity provider with multi-factor authentication support. In-app access is scoped by role down to region, country, and site. Enterprise SSO/SAML is on our roadmap (coming soon).
Security-relevant actions are written to an append-only audit trail — who did what, when — for accountability, forensics, and compliance evidence.
The application is hosted in Germany (Hetzner) and the database runs in Frankfurt (Supabase), on audited EU infrastructure (ISO 27001 / SOC 2 providers), with managed backups and point-in-time recovery.
Internal access follows least-privilege principles, background jobs run with scoped system context, and platform administration is separated from tenant data by design.
Commitments backed by documented processes and rehearsals — not just intentions.
Recovery objectives: RTO 4 hours, RPO 24 hours. The restore path is rehearsed — most recently July 2026, with every table verified row-exact against production — and re-tested quarterly.
A documented incident-response process sits behind our contractual commitment: affected customers are notified within 72 hours of us becoming aware of a personal-data breach.
Running a Data Protection Impact Assessment (GDPR Art. 35 / PDPL)? We provide a support pack with the processor-side facts — data flows, high-risk analysis, and measures. Request it via privacy@sekurad.com.
Full self-service export (JSON) at any time, plus a tamper-evident audit-log export. On termination, data is returned or deleted within 30 days.
The vetted providers we rely on, each bound by data-protection terms.
| Provider | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Application hosting & delivery | Germany (EU) |
| Supabase (PostgreSQL) | Primary database & file storage | EU |
| Clerk Inc. | Authentication & identity | USA (SCCs) |
| OpenAI | AI assistant (Keva) — features you opt into | USA (SCCs, no training on your data) |
| Anthropic | AI assistant (Keva) — features you opt into | USA (SCCs, no training on your data) |
| Resend | Transactional & alert email | USA (SCCs) |
| LemonSqueezy | Billing & payment processing | USA (SCCs) |
| Sentry (Functional Software, Inc.) | Error & performance monitoring (PII disabled) | USA (SCCs) |
Found a security issue? We want to hear from you. Email security@sekurad.com with details and steps to reproduce. We investigate every report and will not pursue good-faith research.
Working toward formal certification (SOC 2 / ISO 27001) — current controls above. Questions from your security team? Reach us at security@sekurad.com.