YARDtwin uses essential cookies for authentication and session management. We don’t currently set analytics or marketing cookies, but our cookie policy categorises them ahead of any future change. Read our Privacy Policy, GDPR Policy, and Cookie Policy.
Kako štitimo podatke klijenata, osiguravamo dostupnost platforme i ostajemo usklađeni s EU GMP Annex 11, 21 CFR Part 11 i GDPR.
YARDtwin radi na Microsoft Azure infrastrukturi s računalnim resursima u Norway East i pohranom podataka, registrom i tajnama u Sweden Central. Svi podaci korisnika ostaju unutar EU/EEA, u skladu s člancima 44–49 GDPR-a.
| Kontrola | Implementacija | Status |
|---|---|---|
| TLS | TLS 1.3 s AES-256-GCM putem Azurea | Verificirano |
| WAF | Azure Front Door WAF (način prevencije) | Aktivno |
| HSTS | Maksimalna starost 2 godine s predučitavanjem | Verificirano |
| Samo HTTPS | Primijenjeno putem App Servicea | Verificirano |
| DB vatrozid | Samo Azure + popis dopuštenih admin IP adresa | Verificirano |
| Kontrola | Implementacija | Status |
|---|---|---|
| Pravila lozinke | 8+ znakova, veliko slovo, malo slovo, broj, specijalni znak | Primijenjeno |
| Provjera kompromitiranih lozinki | HIBP k-anonymity pretraga pri registraciji / promjeni | Aktivno |
| MFA | TOTP (Google/Microsoft Authenticator) | Dostupno |
| SSO/SAML | SAML 2.0 (Azure AD, Okta, Google Workspace) | Aktivno |
| Gruba sila | 5 pokušaja, blokada 15 min (429) | Aktivno |
| JWT tokeni | Pristupni token 1 sat, token za obnovu 7 dana | Aktivno |
| RBAC | 8 uloga s provjerom na razini rute | Aktivno |
| Izolacija tenanta | Svaki upit filtriran po tenant_id | Verificirano |
| Kontrola | Implementacija | Status |
|---|---|---|
| Enkripcija u mirovanju | Azure PostgreSQL AES-256 | Aktivno |
| Enkripcija u prijenosu | TLS 1.3 | Aktivno |
| Hashiranje lozinki | bcrypt (12 rundi) | Aktivno |
| Parametrizirani SQL | 154 upita, 0 konkatenacija | Verificirano |
| Tajni podaci | Azure Key Vault | Aktivno |
| Revizijski trag | Samo-dodavajući, usklađen s ALCOA+ | Aktivno |
All customer data is stored and processed within the EU/EEA — hosted in Microsoft Azure’s Ireland and West/North Europe regions. Creation of resources outside the approved EU regions is blocked at the platform level by an Azure Policy “Deny” rule, so customer data cannot be provisioned outside the EU/EEA. Where a limited-scope sub-processor operates outside the EU (for example AI OCR or email delivery), transfers are governed by EU Standard Contractual Clauses and only the minimum data necessary is sent.
YARDtwin uses a small, vetted set of sub-processors to deliver the service. Each is bound by a Data Processing Agreement. We maintain this register and notify customers of material changes in line with GDPR Article 28.
| Provider | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Microsoft Azure | Cloud infrastructure, database & file-storage hosting | EU/EEA — Ireland, West & North Europe | In-region data residency enforced by Azure Policy; Microsoft DPA |
| Anthropic (Claude) | In-app assistant & document-data extraction | USA | EU Standard Contractual Clauses + DPA; customer data is not used to train AI models |
| Google Cloud (Vision) | Driver-licence & shipping-document OCR | EU / USA | EU Standard Contractual Clauses + DPA; customer data is not used to train AI models |
| ElevenLabs | Text-to-speech voice guidance | USA | EU Standard Contractual Clauses + DPA |
| Stripe | Subscription billing & payment processing | EU / USA | EU Standard Contractual Clauses + DPA; PCI-DSS Level 1 |
| Resend | Transactional email delivery | USA | EU Standard Contractual Clauses + DPA |
YARDtwin uses AI to read driver licences and shipping documents (OCR), to power the in-app assistant, and to generate voice guidance. AI processing is assistive: its output is presented to a person — for example a gate operator confirms every check-in — and YARDtwin does not make automated decisions producing legal or similarly significant effects on individuals (GDPR Article 22).
Strogi CSP s jednokratnim oznakama (nonce) po zahtjevu za skripte (bez unsafe-inline). Potpun skup sigurnosnih zaglavlja vraća se uz svaki odgovor: HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy, Cross-Origin-Opener-Policy, Cross-Origin-Resource-Policy.
Neovisno penetracijsko testiranje 17.–18. travnja 2026. (10 OWASP kategorija, 36 payloada): 0 ranjivosti.Funkcionalno sigurnosno testiranje 11. travnja 2026. koje obuhvaća više od 1 890 API poziva kroz 270 termina: 0 grešaka.Godišnji penetracijský test treće strane planiran, SOC 2 Type II revizija u tijeku.
Pozdravljamo prijave sigurnosnih istraživača. Pošaljite e-mail na admin@yardtwin.coms opisom nalaza i koracima za reprodukciju. Potvrđujemo primitak unutar 2 radna dana i nastojimo ispraviti kritične probleme unutar 7 dana. Molimo vas da ne objavljujete ranjivosti javno prije nego što imamo priliku provesti popravne mjere.
Zadnje ažuriranje: travanj 2026. · yardtwin.com