YARDtwin uses essential cookies for authentication and session management. We don’t currently set analytics or marketing cookies, but our cookie policy categorises them ahead of any future change. Read our Privacy Policy, GDPR Policy, and Cookie Policy.
Kā mēs aizsargājam klientu datus, nodrošinām platformas pieejamību un ievērojam ES GMP Annex 11, 21 CFR Part 11 un GDPR prasības.
YARDtwin darbojas uz Microsoft Azure ar aprēķinu resursu Norvēģijas Austrumos un datiem, reģistru un noslēpumiem Zviedrijas Centrālajā reģionā. Visi klientu dati paliek ES/EEZ robežās, atbilstoši GDPR 44.–49. pantam.
| Kontrole | Ieviešana | Statuss |
|---|---|---|
| TLS | TLS 1.3 ar AES-256-GCM, izmantojot Azure | Verificēts |
| WAF | Azure Front Door WAF (Novēršanas režīms) | Aktīvs |
| HSTS | 2 gadu max-age ar priekšielādi | Verificēts |
| Tikai HTTPS | App Service piemērots | Verificēts |
| DB ugunsmūris | Tikai Azure + administratora IP atļauto saraksts | Verificēts |
| Kontrole | Ieviešana | Statuss |
|---|---|---|
| Paroles politika | 8+ rakstzīmes, lielie, mazie burti, cipars, speciālā rakstzīme | Piemērots |
| Noplūdes pārbaude | HIBP k-anonimitātes uzmeklēšana reģistrācijas / maiņas laikā | Aktīvs |
| MFA | TOTP (Google/Microsoft Authenticator) | Pieejams |
| SSO/SAML | SAML 2.0 (Azure AD, Okta, Google Workspace) | Aktīvs |
| Brutālā spēka aizsardzība | 5 mēģinājumi, 15 minūšu bloķēšana (429) | Aktīvs |
| JWT tokeni | 1 stundas piekļuve, 7 dienu atjaunošana | Aktīvs |
| RBAC | 8 lomas ar maršruta līmeņa kontroli | Aktīvs |
| Nomnieka izolācija | Katrs vaicājums filtrēts pēc tenant_id | Verificēts |
| Kontrole | Ieviešana | Statuss |
|---|---|---|
| Šifrēšana neaktīvā stāvoklī | Azure PostgreSQL AES-256 | Aktīvs |
| Šifrēšana pārsūtīšanas laikā | TLS 1.3 | Aktīvs |
| Paroļu jaukšana | bcrypt (12 kārtas) | Aktīvs |
| Parametrizēts SQL | 154 vaicājumi, 0 savienošana | Verificēts |
| Noslēpumi | Azure Key Vault | Aktīvs |
| Audita pieraksts | Tikai pielikšanas režīmā, atbilst ALCOA+ | Aktīvs |
All customer data is stored and processed within the EU/EEA — hosted in Microsoft Azure’s Ireland and West/North Europe regions. Creation of resources outside the approved EU regions is blocked at the platform level by an Azure Policy “Deny” rule, so customer data cannot be provisioned outside the EU/EEA. Where a limited-scope sub-processor operates outside the EU (for example AI OCR or email delivery), transfers are governed by EU Standard Contractual Clauses and only the minimum data necessary is sent.
YARDtwin uses a small, vetted set of sub-processors to deliver the service. Each is bound by a Data Processing Agreement. We maintain this register and notify customers of material changes in line with GDPR Article 28.
| Provider | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Microsoft Azure | Cloud infrastructure, database & file-storage hosting | EU/EEA — Ireland, West & North Europe | In-region data residency enforced by Azure Policy; Microsoft DPA |
| Anthropic (Claude) | In-app assistant & document-data extraction | USA | EU Standard Contractual Clauses + DPA; customer data is not used to train AI models |
| Google Cloud (Vision) | Driver-licence & shipping-document OCR | EU / USA | EU Standard Contractual Clauses + DPA; customer data is not used to train AI models |
| ElevenLabs | Text-to-speech voice guidance | USA | EU Standard Contractual Clauses + DPA |
| Stripe | Subscription billing & payment processing | EU / USA | EU Standard Contractual Clauses + DPA; PCI-DSS Level 1 |
| Resend | Transactional email delivery | USA | EU Standard Contractual Clauses + DPA |
YARDtwin uses AI to read driver licences and shipping documents (OCR), to power the in-app assistant, and to generate voice guidance. AI processing is assistive: its output is presented to a person — for example a gate operator confirms every check-in — and YARDtwin does not make automated decisions producing legal or similarly significant effects on individuals (GDPR Article 22).
Stingra Content Security Policy ar pieprasījumam specifiskiem nonces skriptiem (nav unsafe-inline). Pilns drošības galvenu komplekts katrai atbildei: HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy, Cross-Origin-Opener-Policy, Cross-Origin-Resource-Policy.
Neatkarīga iespiešanās testēšana 2026. gada 17.–18. aprīlī (10 OWASP kategorijas, 36 slodzes): 0 ievainojamību.Funkcionālā drošības testēšana 2026. gada 11. aprīlī, aptverot 1 890+ API izsaukumus 270 tikšanās reizēs: 0 kļūmju.Ikgadēja trešās puses iespiešanās testēšana plānota, SOC 2 Type II revīzija notiek.
Mēs laipni gaidām drošības pētnieku ziņojumus. Rakstiet uz admin@yardtwin.comar atrades aprakstu un reproducēšanas soļiem. Mēs apstiprinām saņemšanu 2 darba dienu laikā un cenšamies labot kritiskas problēmas 7 dienu laikā. Lūdzu, neizpaudiet ievainojamības publiski, pirms esam varējuši tās novērst.
Pēdējo reizi atjaunināts: 2026. gada aprīlis · yardtwin.com