Trust centre
Security and data location
Firetender’s security model, data location, recovery commitments, and reporting channel.
Last updated: 15 August 2026
Architecture
- A separate organisation identifier is required on tenant-owned records.
- Database Row Level Security and application checks enforce organisation and role boundaries.
- Privileged service credentials remain server-side and are not exposed to browser bundles.
- Authentication uses short-lived sessions and verified email links; stronger owner authentication is part of the commercial launch gate.
Encryption and location
Traffic is encrypted with HTTPS/TLS. The hosted database uses provider encryption at rest. The primary production database is configured in Stockholm, Sweden. Cloudflare processes network traffic at its global edge; approved providers and transfer safeguards are listed on the Subprocessors page.
Application controls
- Role-scoped access for owner/admin, treasurer, secretary, and board readers.
- Human approval before imported payment matches are committed.
- Audit records for material data changes.
- Tenant-scoped full export and separated platform recovery paths.
- Dependency, type, translation, schema, RLS, and production-build checks in the release workflow.
Recovery
Firetender’s commercial production gate requires paid provider backup/PITR, encrypted logical recovery copies, failure alerts, a stated RPO/RTO, and a successfully reconciled isolated restore. Current readiness is shown on the Status page. A logical emailed export is not represented as a substitute for physical database recovery.
Incident response
Firetender triages suspected incidents, preserves evidence, contains affected access, assesses customer and personal-data impact, restores safely, and communicates material facts without undue delay. Customers remain responsible for their regulator and data-subject notifications, with Firetender’s assistance as processor.
Report a vulnerability
Send a confidential report to amundskristiansen@gmail.com with the affected URL, reproducible steps, and impact. Do not access another customer’s data, disrupt service, or publish an unremediated issue. Good-faith reports will be acknowledged within two business days.