Security Policy

Status: Draft for review - This page reflects our current security posture and is under ongoing legal/security review. It may be updated based on specialist feedback.

Effective date: 01 January 2026

Summary We take reasonable and proportionate steps to protect the confidentiality, integrity, and availability of customer data. While no system can be 100% secure, we are committed to continuously improving our controls, promptly addressing vulnerabilities, and notifying customers of material incidents without undue delay. We align with EU GDPR requirements where applicable and act as a Processor for Customer Content under our Terms of Service.

Our security approach (small‑team, pragmatic) - Defense‑in‑depth: layered technical and organizational measures across application, data, and infrastructure layers. - Least privilege: role‑based access with the minimum required permissions for staff and services. - Separation of environments: clear separation between development and production environments. - Secure development practices: code review, dependency scanning, and prompt security updates on a reasonable-effort cadence. - Secrets management: use of environment‑based secrets with restricted access.

Data protection measures - Encryption in transit: All traffic to ITLedger is encrypted with TLS (1.2+). HSTS is enabled where supported. - Encryption at rest: We use managed data services that provide storage encryption at rest where supported by the platform. - Access control: Fine‑grained roles in‑product; staff access to production systems is limited, logged, and based on job role. - Authentication: Support for strong passwords; SSO/IdP integration recommended for customers where available. - Backups and recovery: Regular backups of critical data with periodic restore testing on a reasonable-effort basis. - Logging and monitoring: Application and access logs are retained for operational troubleshooting and security visibility. - Vulnerability management: Routine dependency updates, scanning, and patching. High‑risk issues are prioritized for remediation. - Change management: Controlled deployments with versioning and rollback capability.

Data location and subprocessors - Hosting region: We aim to host primary services and data within the EU where feasible. - Subprocessors: We rely on vetted providers (e.g., hosting, databases, email, payments, analytics). Our current list is available on request via the privacy inbox. We provide notice of material changes and an opportunity to object on reasonable grounds. - International transfers: Where data is transferred outside the EEA/UK/Switzerland to non‑adequate countries, we rely on appropriate safeguards such as the EU Standard Contractual Clauses, with additional technical/organizational measures where appropriate.

Incident response and notifications - Detection & triage: We investigate suspected security events promptly. - Customer notification: If a personal data breach affecting Customer Content occurs, we will notify impacted customers without undue delay, including known details and recommended steps. - Post‑incident review: Material incidents are reviewed and corrective actions are tracked.

Responsible disclosure If you believe you’ve found a vulnerability, please contact us at security@itledger.eu or jorrit@brainforge.nl with steps to reproduce. Do not publicly disclose issues until we’ve had a reasonable opportunity to remediate. Please avoid tests that could degrade availability or affect other customers.

Customer responsibilities (shared responsibility model) - Identity: Use strong, unique passwords; enable SSO/IdP where possible; promptly remove access for departing users. - Authorization: Apply role‑based permissions and the principle of least privilege. - Data governance: Configure retention, exports, and backups appropriate to your needs; avoid uploading sensitive data unless necessary. - Endpoint and network hygiene: Maintain secure endpoints and networks for all users accessing the Service.

Compliance statement - GDPR: When processing Customer Content containing personal data, we act as a Processor under our Terms of Service (see Data Protection and Processing section). We also act as a Controller for website, account, and billing data (see Privacy Policy). - Certifications: We do not currently claim formal security certifications. If/when we obtain any, we will publish them (or summaries) here. - Commitments: We do our utmost within a small‑team setup to maintain appropriate technical and organizational measures, but cannot guarantee absolute security. No formal uptime SLAs apply unless agreed in writing.

Changes to this page We may update this page to reflect improvements, provider changes, or regulatory updates. We’ll post a new effective date for each revision and provide reasonable notice for material changes.

Contact - Security: security@itledger.eu (or jorrit@brainforge.nl) - Privacy: jorrit@brainforge.nl - Operator: Brainforge B.V., Exaltolaan 36, 2841 ME Moordrecht, Netherlands - Websites: https://itledger.eu | https://brainforge.nl