Security
What a security or privacy officer asks before signing: where the data lives, who else touches it, how it is protected, and what happens when something goes wrong. Every line describes this installation as it runs today. Last updated 2026-08-31.
Where your data lives
The application, the database and the backups run on infrastructure of Contabo GmbH, a German company in Munich. The server is in the Hub Europe data centre in Lauterbourg, France (EU).
- Every SBOM, vault document, dossier and audit event lives in the database on that server.
- Backups are stored on EU object storage, encrypted before they leave the server.
- DNS is served by Cloudflare in DNS only mode. No traffic and no personal data passes through Cloudflare, so it is not a subprocessor.
- The public pages load no external fonts, scripts or trackers, so opening one sends no request elsewhere.
How it is protected
- Transport: TLS 1.2 or higher, HTTP/2 and HSTS.
- Passwords: hashed with the ASP.NET Core Identity hasher (PBKDF2).
- Two factor authentication: required for administrators, notifiers and backup notifiers.
- Tenant boundary: every request is scoped to your organisation, and the data of another customer is not reachable from your account.
- Audit trail: append only, with a hash chain per incident, so a changed or removed event is detectable.
- Database role: the application connects as a restricted role that cannot update or delete audit events, SBOM components, vault documents or admin action logs.
- Support access: there is no support login into your organisation. Access happens on the server, by the operator, for one support request, and it stays limited to that request.
- Releases: an OWASP ZAP baseline scan is part of the release checklist.
Backups and recovery
- A backup is taken daily and encrypted with age before it leaves the server.
- 30 daily and 12 monthly copies are kept on EU object storage.
- The audit chain is verified next to each backup, so a broken chain shows up there and not months later.
- A restore is tested at least once a year.
Who else touches your data
The list below is the one the data processing agreement names. Both pages read it from the configuration of this installation, so they can never say something different.
Every subprocessor is assessed before it starts and reviewed once a year. You hear about a new one at least 30 days before it starts, and you may object.
- Contabo GmbH: Hosting of the application, the database and the backups. France (EU). PRD section 8: all application data, files and backups stay on EU infrastructure.
- Stripe Payments Europe Ltd: Subscription billing and invoices. Ireland and United States. Card data and invoices are processed by Stripe, partly in the United States under Stripe's own transfer mechanism.
- Microsoft Ireland Operations Ltd: Transactional email: alerts, reminders and account mail. Exchange Online, EU Data Boundary. to verify until the mail channel is switched on.
When something goes wrong
A personal data breach is reported to you without undue delay, with what is known at that moment. That obligation is in the data processing agreement, not only on this page.
The status page at /status is public and names no customer: the version, whether the database answers, and how fresh each feed is.
Found a security issue? Write to albert@beltar.nl with what you did and what you saw. There is no bounty programme, and a report made in good faith that leaves the data of others alone is welcome.
What we do not claim
This is the part that makes the rest of the page worth reading. None of the following is true today, and this page will change on the day one of them becomes true.
- No certification. There is no ISO 27001 statement, no SOC 2 report and no other audit opinion.
- No penetration test. An external test has not been done. The ZAP baseline scan of the release checklist is not one.
- No encryption at rest beyond the backups. The backups are encrypted; the database volume itself is not.
Beltar B.V., Beatrixstraat 21, 8322 GC Urk, the Netherlands. albert@beltar.nl.