Assoluto

Security

How we protect your data

What the service does today, in plain words. We list what is in place, not plans.

Every supplier and every client sees only their own

Each supplier's portal is a separate tenant. PostgreSQL Row-Level Security filters every query by tenant inside the database, and the application connects with a database role that cannot switch these policies off — so even a bug in the application cannot return another supplier's orders.

Within a portal, each client contact sees only the orders, drawings and material of their own company.

Accounts and sign-in

  • Passwords are stored only as Argon2id hashes — never in readable form.
  • Sign-in, signup, password reset and the contact form are rate-limited against brute force.
  • Password-reset and invitation links work only once.
  • Changing a password signs out every existing session.
  • Session cookies are HttpOnly and SameSite=Lax, and sent only over HTTPS in production.
  • Every form is protected against cross-site request forgery (CSRF).

Hosting and backups

  • The application, the database and uploaded files are hosted by Hetzner Online GmbH in Germany (EU) — a server for the application and database, Hetzner Object Storage for drawings and attachments.
  • All traffic is encrypted with HTTPS (HSTS enabled); pages are served with a strict Content-Security-Policy.
  • The database is backed up daily; backups are kept for 14 days.
  • Emails are delivered through Brevo (France, EU). Card payments, when enabled, are processed by Stripe — we never see card numbers.

Who can see your data

  • You decide who in your company and which of your clients gets an account.
  • Our own operator account cannot browse your portal. Support access is granted to a specific portal only when needed, and the grant is recorded in that portal's audit log.
  • Administrative actions inside your portal are recorded in an audit trail.

Your data stays yours

  • Administrators can export all portal data at any time — orders and customers as CSV, attachments as ZIP.
  • Every user can download their personal data and delete their own account from their profile (GDPR Art. 15, 17 and 20).
  • The source code is open (AGPL-3.0), so anyone can check how it works.

The full list of subprocessors and retention periods is in the Privacy Policy. A data processing agreement (DPA) is available on request.

Who is behind Assoluto

Assoluto is operated by Václav Mudra, Company ID (IČO) 09989978, Lidická 2020/2, 405 02 Děčín.

Write to team@assoluto.eu — we reply within 1 working day. Imprint · Security