← Back to site
Security
We sell proof of security. Here is ours, including what we do not have yet.
Our principles
- Read-only. We read a configuration. We can neither change nor delete it.
- Strict minimum. We only ask for the access the requested checks need.
- Revocable. You cut access whenever you want, without telling us.
- No made-up answers. The verdict comes from a technical check. What cannot be verified is marked “to confirm”.
This site
- Static site, no database and no user accounts.
- No cookies, no advertising trackers, self-hosted fonts.
- HTTPS enforced, strict content security policy, framing protection.
- The free check runs passive checks only and stores nothing.
The app
The app is in early access. Our commitments to every pilot customer:
- hosting in the European Union;
- encryption of data in transit and at rest;
- keeping only the evidence your answers need;
- deletion of your data on request;
- a data processing agreement (GDPR article 28) signed before any processing.
Subprocessors
- Cloudflare: site hosting, DNS and inbound e-mail.
This list is updated before any addition.
What we do not have yet
Hadovia is not SOC 2 or ISO 27001 certified at this time. We would rather say so than let it be assumed.
Reporting a vulnerability
Write to contact@hadovia.com. We acknowledge within three business days and keep you informed of the fix. We take no legal action against research carried out in good faith, without harm to data or service. See also security.txt.