Security

DoraPass is built for financial institutions subject to DORA. We take security seriously because your compliance depends on it.

Data Hosting

All customer data is hosted exclusively in the European Union on Hetzner Online GmbH infrastructure in Germany. We do not use US-based cloud providers for data storage.

  • Location: Hetzner data centers, Germany (EU)
  • Jurisdiction: German and EU law applies
  • Data residency: Your RoI data never leaves the EU

Encryption

In Transit

All connections to DoraPass use TLS 1.3 encryption. We enforce HTTPS across all endpoints with HSTS headers.

At Rest

Database storage uses AES-256 encryption. Backups are encrypted before transfer and storage.

Secrets Management

API keys, credentials, and sensitive configuration are stored encrypted and never committed to source control.

Access Controls

  • Authentication: Secure password hashing with bcrypt, session management with secure cookies
  • Authorization: Role-based access control ensures users only access their own organization's data
  • Admin access: Production access is limited to essential personnel with audit logging
  • Data isolation: Customer data is logically separated at the database level

GDPR Compliance

DoraPass is designed with privacy by default:

  • Data Processing Agreements available upon request
  • Data subject rights supported (access, rectification, erasure, portability)
  • Purpose limitation — we only process data to provide the service
  • Data minimization — we collect only what's necessary

Incident Response

We maintain incident response procedures aligned with GDPR requirements:

  • Detection: Automated monitoring and alerting for security events
  • Response: Documented procedures for containment and investigation
  • Notification: Supervisory authority notification within 72 hours where required
  • Communication: Affected customers notified without undue delay for high-risk incidents

Security Roadmap

We are continuously improving our security posture:

  • EU-only data hosting
  • TLS encryption in transit
  • Encryption at rest
  • GDPR-compliant data handling
  • SOC 2 Type I certification (planned)
  • Penetration testing by third party (planned)

Questions about security?

Contact us at hello@dorapass.com for security inquiries, DPA requests, or to report a vulnerability.