D
Datassier
Legal
Datassier · Legal

Security Policy

Last updated: July 26, 2026

At Datassier (operated by SEEONDATA OÜ), we take the security of your data seriously. This Security Policy describes the technical and organizational measures we implement to protect the data processed through our platform. It describes what we actually do — not an aspirational template.


1. Security Principles

Our security program is built on the following principles:

2. Infrastructure Security

2.1 Hosting

Datassier is hosted on Amazon Web Services (AWS) in the United States (us-east-2, Ohio). AWS maintains industry-standard certifications including SOC 2 Type II and ISO 27001.

2.2 Network Security

2.3 Data Center Security

AWS maintains physical security controls for its data centers, including access control systems, surveillance, environmental controls, and on-site security personnel. AWS publishes independent audit attestations (SOC 2 Type II, ISO 27001) covering these controls.

3. Data Security

3.1 Encryption at Rest

All storage volumes and backups are encrypted at rest using AES-256 (AWS EBS encryption). Encryption keys are managed by AWS Key Management Service with automatic rotation.

3.2 Encryption in Transit

All data transmitted between your browser or application and our servers is encrypted using TLS 1.2 or higher. HTTPS is enforced across all endpoints.

3.3 Data Isolation

Customer data is logically isolated at the application and database layers. The multi-tenant architecture enforces strict tenant boundaries to prevent unauthorized cross-tenant access.

3.4 Data Backup

3.5 Data Deletion

When data deletion is requested or required, data is removed from active systems within 30 days. Backup copies are purged according to the 30-day backup rotation. Physical storage media is decommissioned and destroyed by AWS in accordance with its published procedures.

4. Application Security

4.1 Secure Development

4.2 Vulnerability Management

4.3 Change Management

Changes to production systems follow a documented process including review before deployment and rollback capability via versioned deployments and daily snapshots.

5. Access Control

5.1 Authentication

5.2 Authorization

5.3 Session Management

6. Monitoring and Logging

6.1 Logging

6.2 Monitoring

6.3 Audit Trail

The platform maintains activity logs that provide visibility into actions taken within it, including data modifications and administrative events.

7. Incident Response

7.1 Incident Response Plan

We maintain a documented incident response plan that covers detection, containment, eradication, recovery, and post-incident review. The plan is reviewed and updated regularly.

7.2 Incident Classification

Incidents are classified by severity (Critical, High, Medium, Low) as described in our SLA. Response times and escalation procedures correspond to the severity level.

7.3 Notification

In the event of a security incident affecting customer data, we will notify affected customers without undue delay and within 72 hours, in accordance with the GDPR and our Data Processing Agreement.

7.4 Post-Incident Review

Following any significant security incident, we conduct a thorough post-incident review to identify root causes, assess the effectiveness of our response, and implement improvements to prevent recurrence. Where appropriate, we share learnings with affected customers.

8. Business Continuity and Disaster Recovery

8.1 Resilience Model

Production runs in a single AWS region with daily encrypted backups replicated to a second region (eu-north-1, Stockholm). Recovery from infrastructure failure is performed by restoring from these cross-region backups following a documented procedure.

8.2 Recovery Objectives

8.3 Business Continuity

Our business continuity planning addresses infrastructure outages, security incidents, and personnel unavailability, and is reviewed regularly.

9. Personnel Security

Access to production systems and customer data is limited to SEEONDATA OÜ principals and, where engaged, contractors bound by confidentiality and data protection obligations. Access follows the principle of least privilege and is revoked promptly when no longer required, including credential rotation for shared resources.

10. Third-Party Security

10.1 Vendor Assessment

We assess the security posture of sub-processors before engagement and periodically during the relationship, including review of security certifications and published audit attestations. Our current sub-processors are listed on our Sub-Processors page.

10.2 Contractual Protections

All sub-processors are bound by contractual data protection and security obligations no less protective than those described in this Security Policy and our DPA.

11. Compliance

We align our security practices with recognized frameworks and standards, including:

We pursue formal certifications as our platform matures and will communicate any certifications achieved on our website.

12. Responsible Disclosure

If you discover a security vulnerability in our Service, we encourage responsible disclosure. Please report vulnerabilities to security@datassier.com. We commit to:

Please do not publicly disclose vulnerabilities before we have had a reasonable opportunity to address them.

13. Updates to This Policy

We review and update this Security Policy periodically to reflect changes in our practices, technologies, and regulatory requirements. Material changes will be communicated to customers.

14. Contact

For security-related questions or to report a concern: