YARDtwin uses essential cookies for authentication and session management. We don’t currently set analytics or marketing cookies, but our cookie policy categorises them ahead of any future change. Read our Privacy Policy, GDPR Policy, and Cookie Policy.
Jak chronimy dane klientów, zapewniamy dostępność platformy i zachowujemy zgodność z EU GMP Annex 11, 21 CFR Part 11 oraz GDPR.
YARDtwin działa na Microsoft Azure z obliczeniami w regionie Norway East oraz Sweden Central dla danych, rejestru i sekretów. Wszystkie dane klientów pozostają w obrębie EU/EEA, zgodnie z artykułami 44–49 GDPR.
| Kontrola | Implementacja | Status |
|---|---|---|
| TLS | TLS 1.3 z AES-256-GCM przez Azure | Zweryfikowano |
| WAF | Azure Front Door WAF (tryb prewencyjny) | Aktywny |
| HSTS | max-age 2 lata z preload | Zweryfikowano |
| Tylko HTTPS | Wymuszane przez App Service | Zweryfikowano |
| Zapora bazy danych | Tylko Azure + lista dozwolonych IP administratorów | Zweryfikowano |
| Kontrola | Implementacja | Status |
|---|---|---|
| Polityka haseł | Min. 8 znaków: wielka litera, mała litera, cyfra, znak specjalny | Wymuszony |
| Weryfikacja naruszeń | Wyszukiwanie HIBP k-anonymity przy rejestracji / zmianie hasła | Aktywny |
| MFA | TOTP (Google/Microsoft Authenticator) | Dostępny |
| SSO/SAML | SAML 2.0 (Azure AD, Okta, Google Workspace) | Aktywny |
| Atak brute force | 5 prób, blokada na 15 min (429) | Aktywny |
| Tokeny JWT | Dostęp: 1 godzina, odświeżenie: 7 dni | Aktywny |
| RBAC | 8 ról z wymuszaniem na poziomie tras | Aktywny |
| Izolacja dzierżawcy | Każde zapytanie filtrowane według tenant_id | Zweryfikowano |
| Kontrola | Implementacja | Status |
|---|---|---|
| Szyfrowanie danych w spoczynku | Azure PostgreSQL AES-256 | Aktywny |
| Szyfrowanie danych w tranzycie | TLS 1.3 | Aktywny |
| Haszowanie haseł | bcrypt (12 rund) | Aktywny |
| Parametryzowane SQL | 154 zapytania, 0 konkatenacji | Zweryfikowano |
| Sekrety | Azure Key Vault | Aktywny |
| Ścieżka audytu | Tylko dołączanie, zgodność z ALCOA+ | Aktywny |
All customer data is stored and processed within the EU/EEA — hosted in Microsoft Azure’s Ireland and West/North Europe regions. Creation of resources outside the approved EU regions is blocked at the platform level by an Azure Policy “Deny” rule, so customer data cannot be provisioned outside the EU/EEA. Where a limited-scope sub-processor operates outside the EU (for example AI OCR or email delivery), transfers are governed by EU Standard Contractual Clauses and only the minimum data necessary is sent.
YARDtwin uses a small, vetted set of sub-processors to deliver the service. Each is bound by a Data Processing Agreement. We maintain this register and notify customers of material changes in line with GDPR Article 28.
| Provider | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Microsoft Azure | Cloud infrastructure, database & file-storage hosting | EU/EEA — Ireland, West & North Europe | In-region data residency enforced by Azure Policy; Microsoft DPA |
| Anthropic (Claude) | In-app assistant & document-data extraction | USA | EU Standard Contractual Clauses + DPA; customer data is not used to train AI models |
| Google Cloud (Vision) | Driver-licence & shipping-document OCR | EU / USA | EU Standard Contractual Clauses + DPA; customer data is not used to train AI models |
| ElevenLabs | Text-to-speech voice guidance | USA | EU Standard Contractual Clauses + DPA |
| Stripe | Subscription billing & payment processing | EU / USA | EU Standard Contractual Clauses + DPA; PCI-DSS Level 1 |
| Resend | Transactional email delivery | USA | EU Standard Contractual Clauses + DPA |
YARDtwin uses AI to read driver licences and shipping documents (OCR), to power the in-app assistant, and to generate voice guidance. AI processing is assistive: its output is presented to a person — for example a gate operator confirms every check-in — and YARDtwin does not make automated decisions producing legal or similarly significant effects on individuals (GDPR Article 22).
Rygorystyczna CSP z jednorazowymi nonces per żądanie dla skryptów (bez unsafe-inline). Pełny zestaw nagłówków bezpieczeństwa zwracanych przy każdej odpowiedzi: HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy, Cross-Origin-Opener-Policy, Cross-Origin-Resource-Policy.
Niezależny test penetracyjny przeprowadzony 17–18 kwietnia 2026 (10 kategorii OWASP, 36 ładunków testowych): 0 podatności.Funkcjonalne testy bezpieczeństwa z 11 kwietnia 2026 obejmujące ponad 1 890 wywołań API dla 270 awizacji: 0 błędów.Coroczny pentest przez zewnętrzną firmę zaplanowany; audyt SOC 2 Type II w toku.
Zachęcamy badaczy bezpieczeństwa do zgłaszania znalezisk. Wyślij wiadomość na adres admin@yardtwin.comz opisem znaleziska i krokami reprodukcji. Potwierdzamy odbiór w ciągu 2 dni roboczych i dążymy do usunięcia krytycznych problemów w ciągu 7 dni. Prosimy o nieujawnianie podatności publicznie przed uzyskaniem przez nas możliwości ich naprawienia.
Ostatnia aktualizacja: kwiecień 2026 · yardtwin.com