Risk analysis
We assess the risks of systems and suppliers and review them over time.
Report it responsibly: we listen, verify and fix it. Security begins with code, and with the people who help us improve it.
We assess the risks of systems and suppliers and review them over time.
An incident register with notification deadlines (early warning, notification, final report) and, for personal data, notification to the data protection authority.
Roles and permissions, least privilege, two-step verification for administrators, lockout after repeated attempts.
HTTPS with HSTS, BCrypt-hashed passwords, expiring tokens, sensitive data encrypted where applicable.
A log of administrative actions and security events, with automatic rotation.
Application WAF, blocking and auto-ban of hostile IPs, rate limits, anti-bot and an in-house human check.
Scheduled database backups, with restore tested by the team.
Libraries and fonts hosted by us, no external CDNs for static assets, minimal and updated dependencies.
Talk to the community
See who is online, send private messages and exchange images and files (6 MB max). A free account is required.
Sign in Create an account