Security
How your data is protected
Every Audirium tool runs on the same platform, with the same security underneath. This is what that means in practice.
Security
Every Audirium tool runs on the same platform, with the same security underneath. This is what that means in practice.
Encryption
Your data is encrypted in transit and at rest. Passwords are never stored in readable form, only as an irreversible hash. Sessions expire automatically and are cryptographically unique per user.
Code security
Our code is written with security-first as the starting point. All input is validated before it reaches the server. Injection and cross-site scripting are structurally excluded by the architecture.
Website & platform security
A firewall analyses every incoming request for known attack patterns. Strict browser security headers protect your users on the client side as well. Login and API access are protected against automated attacks.
Data isolation
Your organisation's data is fully separated from that of other organisations, not just logically but also in the database architecture. No cross-contamination, no risk of data leakage between clients.
Testing & monitoring
Every deployment is tested before it goes live. Automated tests run nightly across all endpoints. When anomalies occur, our team receives an alert immediately, before you notice anything.
Privacy & GDPR
Your data is stored in the European Union (Germany), under the GDPR. No tracking, no advertising networks, no third parties looking in. A data processing agreement is available on request.
This describes the measures we take ourselves. It is not a certification and not an audit opinion from a third party.
Report it and we will pick it up. The reporting address is in security.txt, at audirium.net/.well-known/security.txt. Please do not disclose a vulnerability publicly before we have had a chance to respond.
Need a data processing agreement, or have a question about how something is secured? Let us know.