Security

Security is not a feature, it is the architecture.

This page lists only the measures we actually apply in our products and operations. We do not imply a certificate or audit we do not have.

Identity and access

Measures that are standard in the shared foundation our web products are built on.

Roles and permissionsEvery screen and action is tied to a separate permission; users see only what their work requires. Permissions are managed in one place.
Two-step sign-inTwo-step sign-in with an authenticator app (TOTP) can be turned on per user.
Passwords and lockoutAt least 8 characters with a digit and letters; the account locks for 15 minutes after 5 failed attempts.
SessionsA short-lived access token in an HttpOnly cookie; the refresh token changes on every use and sessions can be closed remotely.
Rate limitingPer-IP request limits on sign-in, password and public forms block brute force and form floods.

Audit and traceability

Change logCreating, updating and deleting records is logged with who changed which field, when, with old and new values.
Security logSign-in attempts and session events are kept separately.
Critical commandsIn the industrial product every command written to the field is logged with user and value; selected actions require an e-signature or a second person's approval.
Retention periodsLogs are not kept forever; expired records are deleted by a scheduled job. For example, Bella SCADA keeps the audit log for 1 year, the security log for 2 years and application logs for 90 days.

Data protection

Encryption in transitAll connections run over TLS; HSTS tells the browser to use secure connections only.
PasswordsUser passwords are stored not as plain text but as salted one-way hashes.
Secrets outside the codeConnection strings and keys are kept in an environment file on the server, not in source code.
Retention of personal dataPersonal data is deleted or anonymized when its purpose ends; the periods are listed in the privacy notice.

Installation, backup and environments

Where the data livesIn an on-premise installation the software and data stay on your server; in a cloud installation the data location is written into the contract.
BackupDatabase backup and restore steps are documented and handed over with the installation.
Separate environmentsDevelopment, test and production are separate; we never test with live personal data, test data is synthetic.
Up-to-date dependenciesLibraries in use are kept up to date during maintenance; security patches are part of maintenance.

What we do not claim

  • We do not currently hold ISO 27001, SOC 2 or a similar certificate; when we do, we will list it here with its certificate number.
  • We do not currently publish an independent penetration test report; we open the environment to our clients' own tests and close the findings together.
  • Not every product carries every measure in the same version; which measures are on for each product is stated in writing at the proposal stage.