YARDtwin uses essential cookies for authentication and session management. We don’t currently set analytics or marketing cookies, but our cookie policy categorises them ahead of any future change. Read our Privacy Policy, GDPR Policy, and Cookie Policy.
Wie wir Kundendaten schützen, die Plattformverfügbarkeit gewährleisten und die Anforderungen von EU GMP Annex 11, 21 CFR Part 11 und GDPR erfüllen.
YARDtwin läuft auf Microsoft Azure mit Compute in Norway East und Sweden Central für Daten, Registry und Geheimnisse. Alle Kundendaten verbleiben innerhalb der EU/EEA, konform mit GDPR Artikel 44–49.
| Maßnahme | Umsetzung | Status |
|---|---|---|
| TLS | TLS 1.3 mit AES-256-GCM über Azure | Verifiziert |
| WAF | Azure Front Door WAF (Präventionsmodus) | Aktiv |
| HSTS | 2 Jahre max-age mit Preload | Verifiziert |
| Nur HTTPS | App Service erzwungen | Verifiziert |
| Datenbank-Firewall | Nur Azure + Administrator-IP-Allowlist | Verifiziert |
| Maßnahme | Umsetzung | Status |
|---|---|---|
| Passwortrichtlinie | Mind. 8 Zeichen, Groß-/Kleinbuchstaben, Zahl, Sonderzeichen | Durchgesetzt |
| Datenleck-Prüfung | HIBP k-Anonymitäts-Abfrage bei Registrierung / Änderung | Aktiv |
| MFA | TOTP (Google/Microsoft Authenticator) | Verfügbar |
| SSO/SAML | SAML 2.0 (Azure AD, Okta, Google Workspace) | Aktiv |
| Brute-Force-Schutz | 5 Versuche, 15-minütige Sperrung (429) | Aktiv |
| JWT-Token | 1 Stunde Zugriff, 7 Tage Aktualisierung | Aktiv |
| RBAC | 8 Rollen mit routenbasierter Durchsetzung | Aktiv |
| Mandantenisolierung | Jede Abfrage gefiltert nach tenant_id | Verifiziert |
| Maßnahme | Umsetzung | Status |
|---|---|---|
| Verschlüsselung im Ruhezustand | Azure PostgreSQL AES-256 | Aktiv |
| Verschlüsselung bei der Übertragung | TLS 1.3 | Aktiv |
| Passwort-Hashing | bcrypt (12 Runden) | Aktiv |
| Parametrisiertes SQL | 154 Abfragen, 0 Verkettungen | Verifiziert |
| Geheimnisse | Azure Key Vault | Aktiv |
| Audit-Trail | Nur-Anhänge-Modus, ALCOA+-konform | Aktiv |
All customer data is stored and processed within the EU/EEA — hosted in Microsoft Azure’s Ireland and West/North Europe regions. Creation of resources outside the approved EU regions is blocked at the platform level by an Azure Policy “Deny” rule, so customer data cannot be provisioned outside the EU/EEA. Where a limited-scope sub-processor operates outside the EU (for example AI OCR or email delivery), transfers are governed by EU Standard Contractual Clauses and only the minimum data necessary is sent.
YARDtwin uses a small, vetted set of sub-processors to deliver the service. Each is bound by a Data Processing Agreement. We maintain this register and notify customers of material changes in line with GDPR Article 28.
| Provider | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Microsoft Azure | Cloud infrastructure, database & file-storage hosting | EU/EEA — Ireland, West & North Europe | In-region data residency enforced by Azure Policy; Microsoft DPA |
| Anthropic (Claude) | In-app assistant & document-data extraction | USA | EU Standard Contractual Clauses + DPA; customer data is not used to train AI models |
| Google Cloud (Vision) | Driver-licence & shipping-document OCR | EU / USA | EU Standard Contractual Clauses + DPA; customer data is not used to train AI models |
| ElevenLabs | Text-to-speech voice guidance | USA | EU Standard Contractual Clauses + DPA |
| Stripe | Subscription billing & payment processing | EU / USA | EU Standard Contractual Clauses + DPA; PCI-DSS Level 1 |
| Resend | Transactional email delivery | USA | EU Standard Contractual Clauses + DPA |
YARDtwin uses AI to read driver licences and shipping documents (OCR), to power the in-app assistant, and to generate voice guidance. AI processing is assistive: its output is presented to a person — for example a gate operator confirms every check-in — and YARDtwin does not make automated decisions producing legal or similarly significant effects on individuals (GDPR Article 22).
Strikte CSP mit anforderungsspezifischen Nonces für Skripte (kein unsafe-inline). Vollständiger Satz an Sicherheits-Headern bei jeder Antwort: HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy, Cross-Origin-Opener-Policy, Cross-Origin-Resource-Policy.
Unabhängiger Penetrationstest am 17.–18. April 2026 (10 OWASP-Kategorien, 36 Payloads): 0 Schwachstellen.Funktionaler Sicherheitstest am 11. April 2026 mit über 1.890 API-Aufrufen in 270 Terminen: 0 Fehler.Jährlicher externer Penetrationstest geplant und SOC 2 Type II-Prüfung in Bearbeitung.
Wir begrüßen Meldungen von Sicherheitsforschern. Senden Sie eine E-Mail an admin@yardtwin.commit einer Beschreibung des Befundes und den Schritten zur Reproduktion. Wir bestätigen den Eingang innerhalb von 2 Werktagen und beheben kritische Probleme in der Regel innerhalb von 7 Tagen. Bitte veröffentlichen Sie Sicherheitslücken nicht, bevor wir die Möglichkeit zur Behebung hatten.
Zuletzt aktualisiert: April 2026 · yardtwin.com