At Ubicuto, security is a design decision, not an appendix. This policy describes the measures protecting the service.
Infrastructure
The application and database run on our own infrastructure in Germany; source documents reside in object storage contractually bound to the EU jurisdiction. All customer data remains within the EU. Source documents are stored unaltered, keeping the administration re-derivable and auditable.
Encryption
Traffic is encrypted with TLS 1.3; storage is encrypted at rest (AES-256). Backups are encrypted and remain within the EEA.
Access and isolation
Customers are isolated from each other at database level (row level security). Accounts use two-factor authentication. Internally we apply least privilege; access to production data is restricted and traceable.
Integrations
For external integrations we request only the permissions that are needed — where the provider offers read-only scopes, we use read-only scopes. Access tokens are stored encrypted and can be revoked by the customer.
Continuity
Daily encrypted backups within the EEA, with periodically tested restores. Software changes go through review and automated tests, including a regression suite running on real source document formats.
Reporting a vulnerability
If you suspect a vulnerability, email security@ubicuto.com. We respond within two business days, keep you informed, and will not take legal action against reporters acting in good faith who respect third-party data.