● Legal & security

Safety and Reliability

Protecting your data is our highest priority. We rely on state-of-the-art security standards and proven practices to safeguard the integrity and confidentiality of your information at all times.

Security at RepairCMS

01

Data protection & compliance (GDPR)

  • GDPR compliance: We process data strictly in line with the requirements of the European General Data Protection Regulation (GDPR).
  • Server location: Our infrastructure is hosted exclusively in ISO 27001 certified data centers within the EU.
  • Data processing agreement: We offer you a legally compliant data processing agreement (DPA) in accordance with Article 28 GDPR.
02

Data transfer & encryption

  • HTTPS encryption: All data exchanged between your browser and our servers runs over a securely encrypted connection (TLS/SSL).
  • Encryption at rest: All stored data (data at rest) is protected on our servers with modern encryption methods.
  • Password security: Passwords are never stored in plain text and are secured using strong one-way hashing algorithms.
03

Access control & identity protection

  • Strong passwords & email validation: We enforce strict password policies and verify every sign-up through a confirmation email.
  • Two-factor authentication (2FA): For extra protection of your account, we support sign-in with 2FA.
  • Role-based access rights: Inside the application, a fine-grained system makes sure users can only access the data they are authorized for.
04

Infrastructure & resilience

  • Continuous backups: We create backups continuously. This lets us restore data to any point in time within the retention period.
  • Network security & firewalls: Multi-layer firewalls and modern intrusion detection systems protect our network from unauthorized access.
  • System logs: Audit logs capture security-relevant events to enable a complete analysis when needed.
05

Continuous monitoring & updates

  • Vulnerability scans: Our applications undergo regular automated and manual security testing.
  • Automated patching: We use systems to monitor open-source libraries. Known vulnerabilities are closed by promptly updating the code libraries.
06

Incident management (responding to incidents)

In the event of a data breach, we have a clearly defined process in place. We commit to informing affected parties promptly and transparently. An initial notification is generally sent within 72 hours of an incident becoming known.