Security

How your data is protected

Every Audirium tool runs on the same platform, with the same security underneath. This is what that means in practice.

Encryption

Your data is encrypted in transit and at rest. Passwords are never stored in readable form, only as an irreversible hash. Sessions expire automatically and are cryptographically unique per user.

Code security

Our code is written with security-first as the starting point. All input is validated before it reaches the server. Injection and cross-site scripting are structurally excluded by the architecture.

Website & platform security

A firewall analyses every incoming request for known attack patterns. Strict browser security headers protect your users on the client side as well. Login and API access are protected against automated attacks.

Data isolation

Your organisation's data is fully separated from that of other organisations, not just logically but also in the database architecture. No cross-contamination, no risk of data leakage between clients.

Testing & monitoring

Every deployment is tested before it goes live. Automated tests run nightly across all endpoints. When anomalies occur, our team receives an alert immediately, before you notice anything.

Privacy & GDPR

Your data is stored in the European Union (Germany), under the GDPR. No tracking, no advertising networks, no third parties looking in. A data processing agreement is available on request.

What this is and is not

This describes the measures we take ourselves. It is not a certification and not an audit opinion from a third party.

Found a vulnerability?

Report it and we will pick it up. The reporting address is in security.txt, at audirium.net/.well-known/security.txt. Please do not disclose a vulnerability publicly before we have had a chance to respond.

Questions about security or processing?

Need a data processing agreement, or have a question about how something is secured? Let us know.