Platform Security
DanubeData takes security seriously. Learn about our security measures, best practices, and compliance.
Overview
Security features include:
- Encryption: TLS on public endpoints; server-side encryption for object storage
- Firewalls: Network-level access control
- Isolation: Secure multi-tenant infrastructure
- Compliance: Industry-standard certifications
- Monitoring: 24/7 security monitoring
Data Encryption
Encryption at Rest
Object Storage:
- Server-side encryption with AES-256 (SSE-S3), on by default for new buckets
- Applies to objects written while encryption is on; objects stored before it was turned on stay unencrypted until they are uploaded again
- SSE-KMS with a key you create under Security → KMS keys, or SSE-C with a key your client sends on each request
- Encryption keys are held in HashiCorp Vault
Volumes, databases and snapshots:
- VPS disks, block volumes, and the storage behind managed databases, caches and queues are not encrypted at rest
- Snapshots of those volumes are not encrypted at rest either
- Backup copies in our object store are not guaranteed to be encrypted at rest
- If you need encryption at rest for this data, encrypt it in your application, or inside your server (for example a LUKS-encrypted data volume on a VPS)
Credentials you store with us:
- Environment variables, registry tokens and S3 secret keys are encrypted in our database with AES-256
Encryption in Transit
Public endpoints:
- The dashboard, API and object storage accept HTTPS only, with TLS 1.2 or 1.3; plain HTTP requests are redirected to HTTPS
- Certificates are issued and renewed automatically
Databases:
- Managed databases accept TLS connections; configure your client to require it (for example
sslmode=requireor--ssl-mode=REQUIRED) - PostgreSQL instances can refuse unencrypted connections with Require TLS on the database's Connectivity tab
Inside the platform:
- Private network (VXLAN) traffic between VPS hosts is not encrypted; see Private Networks
- Some traffic between platform components, such as backup transfers to the object store, is not encrypted
Access Control
Authentication
Account Security:
- Strong password requirements
- Two-factor authentication (2FA)
- Passkeys (WebAuthn) for passwordless sign-in
- Google and GitHub social login
- SSH key authentication
- Configurable session idle timeout (24 hours or 3 hours)
API Security:
- API token authentication
- Scoped permissions, including tokens locked to a single project
- Token rotation
- Rate limiting
Sign-in protection:
- New-device sign-in alerts, by email and in-app
- Automatic blocking of repeated failed sign-in attempts, with an alert naming the source IP
- Both alert types are configurable in Notification Preferences
See Account Settings to manage passkeys, connected accounts, session security, and these alerts.
Authorization
Role-Based Access Control (RBAC):
- Owner, admin, member roles
- Project-based permissions
- Least privilege principle
- Audit logging
Resource Permissions:
- Per-resource access control
- Team-based sharing
- Granular permissions
Network Security
Firewalls
Control network access:
- Inbound Rules: Control incoming traffic
- Outbound Rules: Control outgoing traffic
- Stateful Inspection: Track connection state
- Default Deny: Secure by default
Learn more: Firewalls
DDoS Protection
Built-in protection against attacks:
- Layer 3/4 Protection: Network layer
- Layer 7 Protection: Application layer
- Automatic Mitigation: Instant response
- Traffic Scrubbing: Clean malicious traffic
Private Networking
Secure internal communication:
- VLAN Isolation: Tenant separation
- Private IP Space: RFC1918 addresses
- No Internet Routing: Internal only
- Free Bandwidth: No charges
Learn more: Private Networks
Infrastructure Security
Physical Security
Data center security:
- 24/7 Security: Armed guards
- Access Control: Biometric systems
- Surveillance: Video monitoring
- Secure Locations: Undisclosed addresses
Virtualization Security
Secure multi-tenancy:
- Hypervisor Hardening: Minimal attack surface
- Resource Isolation: Dedicated resources
- Kernel Isolation: Separate kernel spaces
- Memory Protection: Isolated memory
Server Security
Secure server infrastructure:
- Hardened OS: Security-focused configuration
- Automatic Updates: Security patches
- Intrusion Detection: Monitoring and alerts
- Malware Protection: Anti-malware systems
Application Security
Database Security
Secure managed databases:
- Encrypted Connections: TLS supported; PostgreSQL can require it
- Access Control: User permissions
- Network Isolation: Firewall rules
- Automatic Backups: Daily backups (not encrypted at rest)
Cache Security
Secure Redis instances:
- Password Protection: Required
- TLS Encryption: Encrypted connections
- Network ACLs: IP-based access
- Private Network: Isolated communication
Compliance
Frameworks and Standards
DanubeData operates and continues to mature its information security practices in alignment with the following frameworks. Where a third-party certification is not yet held, the underlying controls are nevertheless implemented and audited internally.
Frameworks aligned:
- ISO/IEC 27001:2022 framework — Information security management controls implemented across infrastructure, operations, and personnel
- CISPE Code of Conduct for Cloud Infrastructure Service Providers — GDPR-aligned data protection controls for the European cloud market
- GDPR (EU Regulation 2016/679) — Full compliance as a data processor
Underlying infrastructure certifications:
- Hetzner Online GmbH (data center provider) holds ISO/IEC 27001 certification for the Falkenstein and Nuremberg facilities used by DanubeData
Roadmap:
- Independent third-party penetration test (planned annually)
- ISO/IEC 27001 certification of the DanubeData management system (planned)
- CISPE Code of Conduct adherence declaration verified by the official Monitoring Body (in progress)
DanubeData does not currently claim independent certification under SOC 2, PCI DSS, or HIPAA. Customers requiring those certifications should treat the platform as an infrastructure provider whose hardware layer is ISO 27001 certified, while application-layer compliance remains the customer's responsibility under the Shared Responsibility Model.
Data Protection
GDPR Compliance:
- Data processing agreement
- Right to erasure
- Data portability
- Breach notification
Data Residency:
- Data in selected region
- No unauthorized transfers
- Local compliance
- Data sovereignty
Audit and Compliance
Audit Logs:
- Account activity logs
- Resource change logs
- API access logs
- 90-day retention
Compliance Reports:
- Available on request
- Third-party audits
- Penetration testing
- Security assessments
Actions by DanubeData Support
When someone from DanubeData Support changes something on your account, it appears in the Activity Log in your console. Each entry shows:
- Who: "DanubeData Support" and the name of the person who did it
- Which request: the support ticket the action was for, or the reason support recorded when there was no ticket
Support acts on your account only for a support ticket or for a request from you that we have verified. Before an action, our staff have to say which ticket or reason it is for, and your Activity Log shows that next to the action.
Signing in to your account for troubleshooting is recorded too. Your Activity Log shows when support signed in and when they signed out, with the ticket or reason.
If an entry does not match a request you made, contact support@danubedata.ro and tell us the time shown on it.
Security Best Practices
Account Security
- Enable 2FA: Required for all users
- Strong Passwords: 12+ characters, complexity
- Rotate Keys: Regular SSH key rotation
- Limit Access: Only necessary users
Resource Security
- Firewall Rules: Restrict to specific IPs
- Private Networks: Use for internal traffic
- Regular Updates: Keep software updated
- Least Privilege: Minimal permissions
Data Security
- Encrypt Sensitive Data: Application-level encryption
- Regular Backups: Test restoration
- Access Logging: Monitor who accesses what
- Data Classification: Know your data
Application Security
- Security Patches: Apply immediately
- Dependency Updates: Keep dependencies current
- Security Scanning: Regular vulnerability scans
- Secure Configuration: Follow best practices
Incident Response
Security Incidents
Reporting:
- Email: security@danubedata.ro
- Response: Within 1 hour
- 24/7 Security team
Response Process:
- Incident detection
- Containment
- Investigation
- Remediation
- Communication
- Post-mortem
Data Breach
If breach occurs:
- Immediate notification
- Detailed investigation
- Remediation steps
- Regulatory compliance
- Customer communication
Vulnerability Management
Vulnerability Disclosure
Responsible Disclosure:
- Email: security@danubedata.ro
- Response: 24-48 hours
- Bug bounty program
Patch Management:
- Critical: 24 hours
- High: 7 days
- Medium: 30 days
- Low: Next release
Security Updates
Automated security updates:
- OS security patches
- Application updates
- Dependency updates
- Zero-day response
Security Monitoring
24/7 Monitoring
Continuous monitoring of:
- Network traffic
- System logs
- Security events
- Anomaly detection
Threat Detection
Automated Systems:
- Intrusion detection
- Malware scanning
- Behavioral analysis
- Threat intelligence
Security Alerts
Immediate alerts for:
- Unauthorized access attempts
- Unusual activity patterns
- Security violations
- System compromises
Customer Responsibilities
Shared Responsibility
DanubeData Responsibilities:
- Infrastructure security
- Platform security
- Physical security
- Network security
Customer Responsibilities:
- Application security
- Data security
- Access management
- Compliance within applications
Security Checklist
- [ ] Enable two-factor authentication
- [ ] Configure firewall rules
- [ ] Use private networks
- [ ] Require TLS on database connections
- [ ] Regular backup verification
- [ ] Monitor access logs
- [ ] Update applications regularly
- [ ] Security scanning
- [ ] Incident response plan
- [ ] Data classification