Technical and organisational measures protecting Platform data.
The Platform runs on managed cloud infrastructure with EU-region primary data storage. Backups are encrypted at rest.
Application and audit logs are retained and reviewed. Suspicious activity triggers alerts to the on-call engineer.
Automated daily database backups with point-in-time recovery for at least 7 days. Disaster-recovery playbooks are reviewed annually.
Dependencies are monitored for CVEs. Critical patches are applied within 7 days. Security scans run on every deployment.
Incidents are triaged, contained, and communicated to affected controllers without undue delay and, where applicable, within 72 hours of awareness. See the Privacy Policy for statutory notifications.
Report vulnerabilities to security@naviuma.com. Please do not publicly disclose before we confirm a fix.
[CERTIFICATION STATUS — TO BE COMPLETED BY LEGAL/SECURITY OWNER, e.g. SOC 2 Type II in progress, ISO/IEC 27001 planned].
Questions about this document may be sent to legal@naviuma.com.
Naviuma Platform GmbH [Company Legal Address, Munich, Germany]