Ops is a project and invoicing application delivered as a service, with a separate instance for every customer. This summary explains how we protect our customers' data.
Isolation
- One instance per customer. Each customer gets its own application process, its own PostgreSQL database and its own web address (
<customer>.ops.theaumol.com). Different customers' data never shares a database or application memory. - Each instance's database is owned by a role that can reach only that database: one instance cannot read another's data.
- Instances share only the application code and the interface's static files.
Hosting & data location
- IONOS infrastructure in the European Union (Germany).
- Disks encrypted at rest (256-bit AES-XTS, with provider-managed keys held outside the virtual machine).
- All customer data — database and uploaded files — stays in the EU.
Encryption in transit
- TLS 1.2 or later on all web and API traffic. HTTPS only: HTTP requests are redirected. Let's Encrypt certificates with automatic renewal.
- Servers are administered over key-based SSH only, with no passwords. The database is not exposed to the internet.
Authentication & access control
- Sign-in goes through a Zitadel identity service hosted on our own infrastructure. Each customer can use its Microsoft Entra ID or Google Workspace, or email and password with multi-factor authentication.
- Ops does not store user passwords, and federated credentials never reach Ops.
- Permissions are role-based. A deactivated user loses access on their next request.
- Our own administrative access is limited to named individuals, uses SSH keys and is logged.
Backups & recovery
- Nightly encrypted database backups, kept for 7 days on the server and 31 days off-site, in object storage in the EU.
- Backups are encrypted before they leave our infrastructure: the storage provider cannot read them.
- The restore procedure is documented and tested. Restoring a single database takes minutes; the target for rebuilding the whole environment is under 4 hours.
- Recovery point: at most 24 hours (the last nightly backup).
Operational security
- A firewall that denies inbound traffic by default (only the web ports and administrative SSH are open), and
fail2banblocks brute-force attempts. - Automatic security patching on every server.
- Secrets (database passwords, API keys) are kept in files readable only by the server administrator, never in source code.
Data handling
- The customer is the controller; we are the processor. We process personal data only on the customer's documented instructions, under the data processing agreement.
- The sub-processor list shows who else processes data, and where.
- When the service ends, we hand the data back to the customer, then delete it from active systems and, once their retention period has passed, from backups.
What we don't do
- We don't sell or share our customers' data.
- We don't use our customers' data to train AI models.
- We don't access an instance's content except to provide support the customer asks for or to maintain the service, and that access is logged.
Contact
Security questions and vulnerability reports: hola@theaumol.com.