Security Policy
At Datassier (operated by SEEONDATA OÜ), we take the security of your data seriously. This Security Policy describes the technical and organizational measures we implement to protect the data processed through our platform. It describes what we actually do — not an aspirational template.
1. Security Principles
Our security program is built on the following principles:
- Minimal attack surface: We run deliberately small, single-purpose infrastructure with few services exposed, few dependencies, and few third parties involved.
- Least privilege: Access is granted only to the extent necessary and revoked when no longer required.
- Human-in-the-loop for privileged operations: No privileged change reaches production infrastructure without explicit, per-operation approval.
- Transparency: We describe our security practices accurately and promptly disclose incidents affecting our customers.
2. Infrastructure Security
2.1 Hosting
Datassier is hosted on Amazon Web Services (AWS) in the United States (us-east-2, Ohio). AWS maintains industry-standard certifications including SOC 2 Type II and ISO 27001.
2.2 Network Security
- Inbound network access is restricted by AWS security groups to the ports required to operate the service.
- TLS termination is handled by a hardened reverse proxy with automatic certificate provisioning and renewal.
- Administrative SSH access uses key-based authentication only; password authentication is disabled.
- Privileged server operations require out-of-band, per-operation multi-factor (TOTP) approval delivered to a separate device.
- DDoS mitigation is provided at the network layer through AWS.
2.3 Data Center Security
AWS maintains physical security controls for its data centers, including access control systems, surveillance, environmental controls, and on-site security personnel. AWS publishes independent audit attestations (SOC 2 Type II, ISO 27001) covering these controls.
3. Data Security
3.1 Encryption at Rest
All storage volumes and backups are encrypted at rest using AES-256 (AWS EBS encryption). Encryption keys are managed by AWS Key Management Service with automatic rotation.
3.2 Encryption in Transit
All data transmitted between your browser or application and our servers is encrypted using TLS 1.2 or higher. HTTPS is enforced across all endpoints.
3.3 Data Isolation
Customer data is logically isolated at the application and database layers. The multi-tenant architecture enforces strict tenant boundaries to prevent unauthorized cross-tenant access.
3.4 Data Backup
- Automated full-server backups are performed daily.
- Backups are encrypted and stored in a separate AWS region — eu-north-1 (Stockholm), within the European Union — providing cross-region redundancy in a separate failure domain from production.
- Backup retention follows a 30-day rolling schedule.
3.5 Data Deletion
When data deletion is requested or required, data is removed from active systems within 30 days. Backup copies are purged according to the 30-day backup rotation. Physical storage media is decommissioned and destroyed by AWS in accordance with its published procedures.
4. Application Security
4.1 Secure Development
- We follow secure coding practices aligned with OWASP guidelines.
- All changes to production systems are reviewed and tested before deployment.
- Operating system security patches are applied automatically via unattended upgrades.
- Dependencies are monitored for known vulnerabilities and updated promptly.
4.2 Vulnerability Management
- Identified vulnerabilities are triaged by severity and addressed according to defined timelines: critical (24 hours), high (7 days), medium (30 days), low (next release cycle).
- Security reviews of the platform are performed on an ongoing basis. Independent third-party assessment will be engaged as the platform matures, and results will be communicated where appropriate.
4.3 Change Management
Changes to production systems follow a documented process including review before deployment and rollback capability via versioned deployments and daily snapshots.
5. Access Control
5.1 Authentication
- Customer accounts are protected by strong password requirements.
- Administrative and privileged access to Datassier infrastructure uses key-based authentication combined with per-operation multi-factor (TOTP) approval, and is restricted to authorized personnel.
5.2 Authorization
- Role-based access control (RBAC) is enforced across the platform.
- The principle of least privilege governs all access assignments.
- Administrative privileges are limited to a small number of authorized personnel.
- Access permissions are reviewed regularly.
5.3 Session Management
- Sessions are token-based; tokens are regenerated on authentication events.
- Idle sessions time out after a defined period.
6. Monitoring and Logging
6.1 Logging
- Security-relevant events (authentication attempts, administrative actions, data access) are logged.
- Access to logs is restricted to authorized personnel.
- Logs are retained for operational and security analysis.
6.2 Monitoring
- Automated monitoring of service health, resource utilization, and database integrity runs continuously.
- Anomalies trigger real-time alerts to the operations team.
6.3 Audit Trail
The platform maintains activity logs that provide visibility into actions taken within it, including data modifications and administrative events.
7. Incident Response
7.1 Incident Response Plan
We maintain a documented incident response plan that covers detection, containment, eradication, recovery, and post-incident review. The plan is reviewed and updated regularly.
7.2 Incident Classification
Incidents are classified by severity (Critical, High, Medium, Low) as described in our SLA. Response times and escalation procedures correspond to the severity level.
7.3 Notification
In the event of a security incident affecting customer data, we will notify affected customers without undue delay and within 72 hours, in accordance with the GDPR and our Data Processing Agreement.
7.4 Post-Incident Review
Following any significant security incident, we conduct a thorough post-incident review to identify root causes, assess the effectiveness of our response, and implement improvements to prevent recurrence. Where appropriate, we share learnings with affected customers.
8. Business Continuity and Disaster Recovery
8.1 Resilience Model
Production runs in a single AWS region with daily encrypted backups replicated to a second region (eu-north-1, Stockholm). Recovery from infrastructure failure is performed by restoring from these cross-region backups following a documented procedure.
8.2 Recovery Objectives
- RPO target: 24 hours, corresponding to the daily backup cadence.
- RTO target: 24 hours for full infrastructure restoration; most failure scenarios are recoverable substantially faster.
8.3 Business Continuity
Our business continuity planning addresses infrastructure outages, security incidents, and personnel unavailability, and is reviewed regularly.
9. Personnel Security
Access to production systems and customer data is limited to SEEONDATA OÜ principals and, where engaged, contractors bound by confidentiality and data protection obligations. Access follows the principle of least privilege and is revoked promptly when no longer required, including credential rotation for shared resources.
10. Third-Party Security
10.1 Vendor Assessment
We assess the security posture of sub-processors before engagement and periodically during the relationship, including review of security certifications and published audit attestations. Our current sub-processors are listed on our Sub-Processors page.
10.2 Contractual Protections
All sub-processors are bound by contractual data protection and security obligations no less protective than those described in this Security Policy and our DPA.
11. Compliance
We align our security practices with recognized frameworks and standards, including:
- GDPR (Regulation (EU) 2016/679)
- OWASP Application Security guidelines
- SOC 2 principles (Trust Services Criteria)
We pursue formal certifications as our platform matures and will communicate any certifications achieved on our website.
12. Responsible Disclosure
If you discover a security vulnerability in our Service, we encourage responsible disclosure. Please report vulnerabilities to security@datassier.com. We commit to:
- Acknowledging your report within 2 business days;
- Providing an initial assessment within 7 business days;
- Keeping you informed of remediation progress;
- Not pursuing legal action against researchers who act in good faith and comply with this policy.
Please do not publicly disclose vulnerabilities before we have had a reasonable opportunity to address them.
13. Updates to This Policy
We review and update this Security Policy periodically to reflect changes in our practices, technologies, and regulatory requirements. Material changes will be communicated to customers.
14. Contact
For security-related questions or to report a concern:
- Security Team: security@datassier.com
- Data Protection: privacy@datassier.com