Security & transparency

Our own EU infrastructure, no hyperscaler, GDPR-compliant. What we check, what we store, and what we do not.

EU operations

Infrastructure

Everything we operate ourselves is located in the EU: scanners, database, monitoring and email dispatch. No AWS, no Google Cloud, no Azure. Where we use service providers, they are listed together with their location in the privacy policy and in the list of sub-processors — some of them with a third-country element, payment processing above all.

Hosting Hetzner (Falkenstein, DE) German provider, ISO 27001
DNS Bunny.net (Ljubljana, SI) EU company, GDPR-compliant
Email Scaleway TEM (Paris, FR) EU provider, RFC 8058
Database PostgreSQL (self-managed) On our own server, no cloud database
Scanner transparency

What our scanners do — and what they do not

What our scanners do

  • Request the web address you enter over HTTP(S) and make selected additional requests
  • Analyse the publicly available response headers
  • Query DNS records via DoH (DNS over HTTPS)
  • Open an SMTP connection for email protocol checks

What our scanners do NOT do

  • No penetration tests and no active attacks
  • No enumeration of directories or files
  • No site-wide crawling
  • No storage of the content of your website
  • No access to protected areas

Legal basis: our scanners work like an ordinary browser request. Only publicly accessible information is checked.

Our own security

We scan ourselves — with the same tools our customers use. Current score: check it yourself →

A+ security score on our own platform
Nonce-based Content Security Policy
Trusted Types against DOM XSS
HSTS with preload (max-age 2 years)
All cross-origin headers set (COEP, COOP, CORP)
Permissions-Policy: all APIs disabled
Rate limiting at API level (nginx + application)
Session management with Better Auth
Device recognition for unknown logins
Standards & frameworks

What we check against

BSI Grundschutz APP.3.1 Web applications as the basis for checking
OWASP ASVS and the API Security Top 10 as a reference
PCI DSS 4.0 Source visibility as an input to the inventory level of Req. 6.4.3 — Req. 11.6.1 (header and content tamper detection) and script integrity (SRI) are not covered
SPF, DKIM, DMARC Established email authentication standards (RFC 7208/6376/7489) that the BSI recommends for email security
RFC 9116 security.txt standard
NIS2 risk management Technical findings on externally visible configuration as input to risk documentation — no conformity assessment

Questions about security?

Transparency matters to us. If you have questions about our infrastructure, our data processing or how the scanners work: get in touch.