Security

Version 1.1 · Effective 2026-08-30

The short version. We encrypt your data at rest and in transit. We restrict who can access production systems. We log access and breach attempts. We are happy to receive vulnerability reports at security@eltria.de and ask researchers to follow responsible disclosure. We do not yet hold formal certifications such as ISO 27001 — we will say so if we ever do.

1. Security controls

This is the engineering reality of how we protect your data, written without marketing.

1.1 Encryption

1.2 Access control

1.3 Authentication and session management

1.4 Logging and monitoring

1.5 Backups and disaster recovery

1.6 Network and infrastructure

2. Compliance

We are honest about what we have and what we do not have.

2.1 What we have

2.2 What we do not have

We will update this section if any of the above changes. We commit not to claim certifications we do not hold.

3. Reporting a vulnerability

If you have found a vulnerability in the Service, we want to hear from you. Please email security@eltria.de with:

3.1 Responsible disclosure

We ask that you:

In return, we commit to:

3.2 Out of scope

The following are generally not in scope for our security reports:

4. Breach notification

If we discover a personal data breach, our obligations are described in our Privacy Policy §6: we notify the supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33, and we notify affected users without undue delay where the breach is likely to result in a high risk to their rights and freedoms (Article 34). Where a US state breach-notification statute applies (e.g. Cal. Civ. Code § 1798.82, RCW 19.255), we follow that statute's timing in addition to the GDPR commitment.

5. Contact

Vulnerability reportssecurity@eltria.de
General privacyprivacy@eltria.de
Postal addressEltria UG (haftungsbeschränkt), Kolonnenstraße 8, 10827 Berlin, Germany