YARDtwin uses essential cookies for authentication and session management. We don’t currently set analytics or marketing cookies, but our cookie policy categorises them ahead of any future change. Read our Privacy Policy, GDPR Policy, and Cookie Policy.
Come proteggiamo i dati dei clienti, garantiamo la disponibilità della piattaforma e manteniamo la conformità con EU GMP Annex 11, 21 CFR Part 11 e GDPR.
YARDtwin è ospitato su Microsoft Azure con elaborazione in Norway East e Sweden Central per dati, registry e segreti. Tutti i dati dei clienti rimangono all'interno dell'UE/SEE, in conformità con gli articoli 44–49 del GDPR.
| Controllo | Implementazione | Stato |
|---|---|---|
| TLS | TLS 1.3 con AES-256-GCM tramite Azure | Verificato |
| WAF | Azure Front Door WAF (modalità Prevenzione) | Attivo |
| HSTS | max-age di 2 anni con preload | Verificato |
| Solo HTTPS | Applicato da App Service | Verificato |
| Firewall DB | Solo Azure + allowlist IP amministratore | Verificato |
| Controllo | Implementazione | Stato |
|---|---|---|
| Policy password | 8+ caratteri, maiuscola, minuscola, numero, carattere speciale | Applicato |
| Verifica violazioni | Ricerca HIBP k-anonymity alla registrazione / modifica | Attivo |
| MFA | TOTP (Google/Microsoft Authenticator) | Disponibile |
| SSO/SAML | SAML 2.0 (Azure AD, Okta, Google Workspace) | Attivo |
| Forza bruta | 5 tentativi, blocco di 15 min (429) | Attivo |
| Token JWT | Accesso 1 ora, aggiornamento 7 giorni | Attivo |
| RBAC | 8 ruoli con applicazione a livello di percorso | Attivo |
| Isolamento tenant | Ogni query filtrata per tenant_id | Verificato |
| Controllo | Implementazione | Stato |
|---|---|---|
| Cifratura a riposo | Azure PostgreSQL AES-256 | Attivo |
| Cifratura in transito | TLS 1.3 | Attivo |
| Hashing password | bcrypt (12 round) | Attivo |
| SQL parametrizzato | 154 query, 0 concatenazioni | Verificato |
| Segreti | Azure Key Vault | Attivo |
| Audit trail | Solo aggiunta, conforme ALCOA+ | Attivo |
All customer data is stored and processed within the EU/EEA — hosted in Microsoft Azure’s Ireland and West/North Europe regions. Creation of resources outside the approved EU regions is blocked at the platform level by an Azure Policy “Deny” rule, so customer data cannot be provisioned outside the EU/EEA. Where a limited-scope sub-processor operates outside the EU (for example AI OCR or email delivery), transfers are governed by EU Standard Contractual Clauses and only the minimum data necessary is sent.
YARDtwin uses a small, vetted set of sub-processors to deliver the service. Each is bound by a Data Processing Agreement. We maintain this register and notify customers of material changes in line with GDPR Article 28.
| Provider | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Microsoft Azure | Cloud infrastructure, database & file-storage hosting | EU/EEA — Ireland, West & North Europe | In-region data residency enforced by Azure Policy; Microsoft DPA |
| Anthropic (Claude) | In-app assistant & document-data extraction | USA | EU Standard Contractual Clauses + DPA; customer data is not used to train AI models |
| Google Cloud (Vision) | Driver-licence & shipping-document OCR | EU / USA | EU Standard Contractual Clauses + DPA; customer data is not used to train AI models |
| ElevenLabs | Text-to-speech voice guidance | USA | EU Standard Contractual Clauses + DPA |
| Stripe | Subscription billing & payment processing | EU / USA | EU Standard Contractual Clauses + DPA; PCI-DSS Level 1 |
| Resend | Transactional email delivery | USA | EU Standard Contractual Clauses + DPA |
YARDtwin uses AI to read driver licences and shipping documents (OCR), to power the in-app assistant, and to generate voice guidance. AI processing is assistive: its output is presented to a person — for example a gate operator confirms every check-in — and YARDtwin does not make automated decisions producing legal or similarly significant effects on individuals (GDPR Article 22).
CSP restrittiva con nonce per richiesta sugli script (nessun unsafe-inline). Set completo di header di sicurezza restituiti ad ogni risposta: HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy, Cross-Origin-Opener-Policy, Cross-Origin-Resource-Policy.
Penetration testing indipendente il 17–18 aprile 2026 (10 categorie OWASP, 36 payload): 0 vulnerabilità.Test di sicurezza funzionale dell'11 aprile 2026 su oltre 1.890 chiamate API per 270 appuntamenti: 0 errori.Pentest annuale di terze parti pianificato e audit SOC 2 Type II in corso.
Accogliamo con favore le segnalazioni dei ricercatori di sicurezza. Invia un'e-mail a admin@yardtwin.comcon una descrizione della vulnerabilità e i passaggi per riprodurla. Confermiamo la ricezione entro 2 giorni lavorativi e ci impegniamo a correggere i problemi critici entro 7 giorni. Si prega di non divulgare pubblicamente le vulnerabilità prima che abbiamo avuto la possibilità di porvi rimedio.
Ultimo aggiornamento: aprile 2026 · yardtwin.com