YARDtwin uses essential cookies for authentication and session management. We don’t currently set analytics or marketing cookies, but our cookie policy categorises them ahead of any future change. Read our Privacy Policy, GDPR Policy, and Cookie Policy.
How we protect customer data, keep the platform available, and stay compliant with EU GMP Annex 11, 21 CFR Part 11, and GDPR.
YARDtwin runs on Microsoft Azure with Norway East compute and Sweden Central for data, registry, and secrets. All customer data stays within the EU/EEA, compliant with GDPR Articles 44–49.
| Control | Implementation | Status |
|---|---|---|
| TLS | TLS 1.3 with AES-256-GCM via Azure | Verified |
| WAF | Azure Front Door WAF (Prevention mode) | Active |
| HSTS | 2-year max-age with preload | Verified |
| HTTPS-only | App Service enforced | Verified |
| DB firewall | Azure-only + admin IP allowlist | Verified |
| Control | Implementation | Status |
|---|---|---|
| Password policy | 8+ chars, upper, lower, number, special | Enforced |
| Breach check | HIBP k-anonymity lookup on signup / change | Active |
| MFA | TOTP (Google/Microsoft Authenticator) | Available |
| SSO/SAML | SAML 2.0 (Azure AD, Okta, Google Workspace) | Active |
| Brute force | 5 attempts, 15-min lockout (429) | Active |
| JWT tokens | 1-hour access, 7-day refresh | Active |
| RBAC | 8 roles with route-level enforcement | Active |
| Tenant isolation | Every query filtered by tenant_id | Verified |
| Control | Implementation | Status |
|---|---|---|
| Encryption at rest | Azure PostgreSQL AES-256 | Active |
| Encryption in transit | TLS 1.3 | Active |
| Password hashing | bcrypt (12 rounds) | Active |
| Parameterized SQL | 154 queries, 0 concatenation | Verified |
| Secrets | Azure Key Vault | Active |
| Audit trail | Append-only, ALCOA+ compliant | Active |
All customer data is stored and processed within the EU/EEA — hosted in Microsoft Azure’s Ireland and West/North Europe regions. Creation of resources outside the approved EU regions is blocked at the platform level by an Azure Policy “Deny” rule, so customer data cannot be provisioned outside the EU/EEA. Where a limited-scope sub-processor operates outside the EU (for example AI OCR or email delivery), transfers are governed by EU Standard Contractual Clauses and only the minimum data necessary is sent.
YARDtwin uses a small, vetted set of sub-processors to deliver the service. Each is bound by a Data Processing Agreement. We maintain this register and notify customers of material changes in line with GDPR Article 28.
| Provider | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Microsoft Azure | Cloud infrastructure, database & file-storage hosting | EU/EEA — Ireland, West & North Europe | In-region data residency enforced by Azure Policy; Microsoft DPA |
| Anthropic (Claude) | In-app assistant & document-data extraction | USA | EU Standard Contractual Clauses + DPA; customer data is not used to train AI models |
| Google Cloud (Vision) | Driver-licence & shipping-document OCR | EU / USA | EU Standard Contractual Clauses + DPA; customer data is not used to train AI models |
| ElevenLabs | Text-to-speech voice guidance | USA | EU Standard Contractual Clauses + DPA |
| Stripe | Subscription billing & payment processing | EU / USA | EU Standard Contractual Clauses + DPA; PCI-DSS Level 1 |
| Resend | Transactional email delivery | USA | EU Standard Contractual Clauses + DPA |
YARDtwin uses AI to read driver licences and shipping documents (OCR), to power the in-app assistant, and to generate voice guidance. AI processing is assistive: its output is presented to a person — for example a gate operator confirms every check-in — and YARDtwin does not make automated decisions producing legal or similarly significant effects on individuals (GDPR Article 22).
Strict CSP with per-request nonces on scripts (no unsafe-inline). Full set of security headers returned on every response: HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy, Cross-Origin-Opener-Policy, Cross-Origin-Resource-Policy.
Independent penetration testing on 17–18 April 2026 (10 OWASP categories, 36 payloads): 0 vulnerabilities.Functional security testing on 11 April 2026 covering 1,890+ API calls across 270 appointments: 0 failures.Annual third-party pentest scheduled and SOC 2 Type II audit in progress.
We welcome reports from security researchers. Email admin@yardtwin.comwith a description of the finding and steps to reproduce. We acknowledge receipt within 2 business days and aim to patch critical issues within 7 days. Please do not publicly disclose vulnerabilities before we have had a chance to remediate.
Last updated: April 2026 · yardtwin.com