[ SECURITY & COMPLIANCE ]
RODO / GDPR
Full compliance
NIS2 / UKSC
Art. 21(2)(g)
DORA / KNF
Financial sector
OWASP ASVS
Testing methodology
WCAG 2.2 AA
Accessibility
Table of Contents
1. Infrastructure 2. Data Protection 3. Application Security 4. Security Testing 5. Business Continuity 6. Organizational Security 7. Vulnerability Reporting 8. Regulatory Compliance 9. Documents1. Infrastructure
The platform is hosted in certified data centres in the European Union (Frankfurt region). The infrastructure provider (AWS) holds ISO 27001 and SOC 1/2/3 certifications. Payments are handled by Stripe (PCI DSS Level 1) — the platform does not store payment card data.
- Network traffic routed through CDN with WAF and DDoS protection
- Origin server not directly accessible from the internet
- Connections exclusively via HTTPS with HSTS enforcement
- Administrative access via cryptographic keys only
2. Data Protection
Encryption
- Data encrypted at rest at database and disk level
- Sensitive fields (integration passwords, tokens, secrets) encrypted with additional application-level encryption with key rotation
- User passwords stored using a modern hashing algorithm per OWASP recommendations
- Data transmission secured with TLS 1.3
Retention & Deletion
- Defined retention periods for each data category
- Automated data cleanup after retention period expires
- Right to delete account and export data (Art. 17 and 20 GDPR) available from user panel
3. Application Security
Authentication
- Multi-factor authentication (MFA) required for all users
- Hardware key support (FIDO2/WebAuthn) and authenticator apps (TOTP)
- Single Sign-On (SAML 2.0) with automatic user sync (SCIM 2.0)
Threat Protection
- Content Security Policy with XSS protection
- Protection against CSRF, IDOR, SQL Injection and other OWASP Top 10 attacks
- Rate limiting protecting against brute-force attacks and abuse
- Concurrent session limit per user
- Security policy violation monitoring (CSP reporting)
4. Security Testing
- Regular penetration tests conducted per OWASP methodology
- Static application security testing (SAST) in CI on every code change
- Continuous dependency monitoring for known vulnerabilities (CVE)
- Automatic security alerts for new component vulnerabilities
Security Test Report
Latest audit summary available on request for customers and partners.
Contact: kontakt@ks-cyber.pl
Latest audit summary available on request for customers and partners.
Contact: kontakt@ks-cyber.pl
5. Business Continuity
- Automatic daily backups of infrastructure and database
- Real-time availability and performance monitoring
- Error tracking with automatic team alerts
- Global CDN network ensuring high availability
- Asynchronous task processing eliminating single points of failure
6. Organizational Security
- Information security policy aligned with industry best practices
- Regular team training on secure software development
- Incident response procedure with customer notification per Art. 33 GDPR (72h)
- Data classification and access control based on least privilege principle
7. Vulnerability Reporting
We encourage responsible disclosure of security vulnerabilities. Please contact us before public disclosure.
Security Contact
Email: kontakt@ks-cyber.pl
security.txt: /.well-known/security.txt
We commit to responding within 48 business hours.
Email: kontakt@ks-cyber.pl
security.txt: /.well-known/security.txt
We commit to responding within 48 business hours.
8. Regulatory Compliance
RODO / GDPR
- Records of Processing Activities (Art. 30)
- Data Protection Impact Assessment — DPIA (Art. 35)
- Data Processing Agreement — DPA (Art. 28)
- Right of access (Art. 15), erasure (Art. 17), portability (Art. 20)
- Breach notification within 72h (Art. 33)
- Subprocessor registry
NIS2 / UKSC
- Cybersecurity training for employees — Art. 21(2)(g)
- Documenting training programs and certificates
- Phishing simulations with automatic remediation
- Executive reporting — Art. 20
DORA / KNF
- Dedicated training modules for the financial sector
- Digital resilience testing (phishing simulations + USB Drop)
- Compliance reporting for regulated institutions
Audit trail
All security events are logged with export capability. Full audit trail covers authentication, configuration changes, data exports, and administrative actions.
9. Documents
Additional documents (security audit report, technical details) available on request for Enterprise customers.
Contact: kontakt@ks-cyber.pl
Contact: kontakt@ks-cyber.pl