Security
DoraPass is built for financial institutions subject to DORA. We take security seriously because your compliance depends on it.
Data Hosting
All customer data is hosted exclusively in the European Union on Hetzner Online GmbH infrastructure in Germany. We do not use US-based cloud providers for data storage.
- •Location: Hetzner data centers, Germany (EU)
- •Jurisdiction: German and EU law applies
- •Data residency: Your RoI data never leaves the EU
Encryption
In Transit
All connections to DoraPass use TLS 1.3 encryption. We enforce HTTPS across all endpoints with HSTS headers.
At Rest
Database storage uses AES-256 encryption. Backups are encrypted before transfer and storage.
Secrets Management
API keys, credentials, and sensitive configuration are stored encrypted and never committed to source control.
Access Controls
- •Authentication: Secure password hashing with bcrypt, session management with secure cookies
- •Authorization: Role-based access control ensures users only access their own organization's data
- •Admin access: Production access is limited to essential personnel with audit logging
- •Data isolation: Customer data is logically separated at the database level
GDPR Compliance
DoraPass is designed with privacy by default:
- •Data Processing Agreements available upon request
- •Data subject rights supported (access, rectification, erasure, portability)
- •Purpose limitation — we only process data to provide the service
- •Data minimization — we collect only what's necessary
Incident Response
We maintain incident response procedures aligned with GDPR requirements:
- •Detection: Automated monitoring and alerting for security events
- •Response: Documented procedures for containment and investigation
- •Notification: Supervisory authority notification within 72 hours where required
- •Communication: Affected customers notified without undue delay for high-risk incidents
Security Roadmap
We are continuously improving our security posture:
- ✓EU-only data hosting
- ✓TLS encryption in transit
- ✓Encryption at rest
- ✓GDPR-compliant data handling
- ○SOC 2 Type I certification (planned)
- ○Penetration testing by third party (planned)
Questions about security?
Contact us at hello@dorapass.com for security inquiries, DPA requests, or to report a vulnerability.