YARDtwin uses essential cookies for authentication and session management. We don’t currently set analytics or marketing cookies, but our cookie policy categorises them ahead of any future change. Read our Privacy Policy, GDPR Policy, and Cookie Policy.
Hoe wij klantgegevens beschermen, het platform beschikbaar houden en voldoen aan EU GMP Annex 11, 21 CFR Part 11 en GDPR.
YARDtwin draait op Microsoft Azure met Norway East voor rekenkracht en Sweden Central voor data, registry en secrets. Alle klantgegevens blijven binnen de EU/EEA, conform GDPR-artikelen 44–49.
| Maatregel | Implementatie | Status |
|---|---|---|
| TLS | TLS 1.3 met AES-256-GCM via Azure | Geverifieerd |
| WAF | Azure Front Door WAF (preventiemodus) | Actief |
| HSTS | 2-jaar max-age met preload | Geverifieerd |
| Alleen HTTPS | App Service afgedwongen | Geverifieerd |
| DB-firewall | Alleen Azure + admin IP-allowlist | Geverifieerd |
| Maatregel | Implementatie | Status |
|---|---|---|
| Wachtwoordbeleid | 8+ tekens, hoofd-, kleine letters, cijfer, speciaal teken | Afgedwongen |
| Lek-controle | HIBP k-anonimiteit lookup bij aanmelden / wijzigen | Actief |
| MFA | TOTP (Google/Microsoft Authenticator) | Beschikbaar |
| SSO/SAML | SAML 2.0 (Azure AD, Okta, Google Workspace) | Actief |
| Brute force | 5 pogingen, 15 min. vergrendeling (429) | Actief |
| JWT-tokens | 1 uur toegang, 7 dagen vernieuwen | Actief |
| RBAC | 8 rollen met handhaving op routeniveau | Actief |
| Tenant-isolatie | Elke query gefilterd op tenant_id | Geverifieerd |
| Maatregel | Implementatie | Status |
|---|---|---|
| Versleuteling in rust | Azure PostgreSQL AES-256 | Actief |
| Versleuteling in transit | TLS 1.3 | Actief |
| Wachtwoord-hashing | bcrypt (12 rondes) | Actief |
| Geparametriseerde SQL | 154 queries, 0 concatenatie | Geverifieerd |
| Geheimen | Azure Key Vault | Actief |
| Audittrail | Append-only, ALCOA+-conform | Actief |
All customer data is stored and processed within the EU/EEA — hosted in Microsoft Azure’s Ireland and West/North Europe regions. Creation of resources outside the approved EU regions is blocked at the platform level by an Azure Policy “Deny” rule, so customer data cannot be provisioned outside the EU/EEA. Where a limited-scope sub-processor operates outside the EU (for example AI OCR or email delivery), transfers are governed by EU Standard Contractual Clauses and only the minimum data necessary is sent.
YARDtwin uses a small, vetted set of sub-processors to deliver the service. Each is bound by a Data Processing Agreement. We maintain this register and notify customers of material changes in line with GDPR Article 28.
| Provider | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Microsoft Azure | Cloud infrastructure, database & file-storage hosting | EU/EEA — Ireland, West & North Europe | In-region data residency enforced by Azure Policy; Microsoft DPA |
| Anthropic (Claude) | In-app assistant & document-data extraction | USA | EU Standard Contractual Clauses + DPA; customer data is not used to train AI models |
| Google Cloud (Vision) | Driver-licence & shipping-document OCR | EU / USA | EU Standard Contractual Clauses + DPA; customer data is not used to train AI models |
| ElevenLabs | Text-to-speech voice guidance | USA | EU Standard Contractual Clauses + DPA |
| Stripe | Subscription billing & payment processing | EU / USA | EU Standard Contractual Clauses + DPA; PCI-DSS Level 1 |
| Resend | Transactional email delivery | USA | EU Standard Contractual Clauses + DPA |
YARDtwin uses AI to read driver licences and shipping documents (OCR), to power the in-app assistant, and to generate voice guidance. AI processing is assistive: its output is presented to a person — for example a gate operator confirms every check-in — and YARDtwin does not make automated decisions producing legal or similarly significant effects on individuals (GDPR Article 22).
Strikte CSP met per-verzoek nonces op scripts (geen unsafe-inline). Volledige set beveiligingsheaders bij elk antwoord: HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy, Cross-Origin-Opener-Policy, Cross-Origin-Resource-Policy.
Onafhankelijke penetratietest op 17–18 april 2026 (10 OWASP-categorieën, 36 payloads): 0 kwetsbaarheden.Functionele beveiligingstesting op 11 april 2026 met meer dan 1.890 API-aanroepen over 270 afspraken: 0 fouten.Jaarlijkse externe pentest gepland en SOC 2 Type II-audit in uitvoering.
Wij verwelkomen meldingen van beveiligingsonderzoekers. Stuur een e-mail naar admin@yardtwin.commet een beschrijving van de bevinding en stappen om deze te reproduceren. Wij bevestigen ontvangst binnen 2 werkdagen en streven ernaar kritieke problemen binnen 7 dagen te verhelpen. Gelieve kwetsbaarheden niet openbaar te maken voordat wij de kans hebben gehad deze te verhelpen.
Laatst bijgewerkt: april 2026 · yardtwin.com