Cookie preferences

YARDtwin uses essential cookies for authentication and session management. We don’t currently set analytics or marketing cookies, but our cookie policy categorises them ahead of any future change. Read our Privacy Policy, GDPR Policy, and Cookie Policy.

← Back to home

Security at YARDtwin

How we protect customer data, keep the platform available, and stay compliant with EU GMP Annex 11, 21 CFR Part 11, and GDPR.

Score 4.8/5.00 pentest findingsEU/EEA data residencyGDPR compliant

Platform & hosting

YARDtwin runs on Microsoft Azure with Norway East compute and Sweden Central for data, registry, and secrets. All customer data stays within the EU/EEA, compliant with GDPR Articles 44–49.

  • App Service (Linux Container) — Norway East
  • Azure PostgreSQL Flexible Server — Sweden Central
  • Azure Blob Storage — Norway East, private containers
  • Azure Key Vault — Sweden Central, RBAC-controlled
  • Azure Front Door + WAF — Prevention mode
  • Log Analytics + Microsoft Sentinel — 90-day retention

Network & transport security

ControlImplementationStatus
TLSTLS 1.3 with AES-256-GCM via AzureVerified
WAFAzure Front Door WAF (Prevention mode)Active
HSTS2-year max-age with preloadVerified
HTTPS-onlyApp Service enforcedVerified
DB firewallAzure-only + admin IP allowlistVerified

Authentication & access control

ControlImplementationStatus
Password policy8+ chars, upper, lower, number, specialEnforced
Breach checkHIBP k-anonymity lookup on signup / changeActive
MFATOTP (Google/Microsoft Authenticator)Available
SSO/SAMLSAML 2.0 (Azure AD, Okta, Google Workspace)Active
Brute force5 attempts, 15-min lockout (429)Active
JWT tokens1-hour access, 7-day refreshActive
RBAC8 roles with route-level enforcementActive
Tenant isolationEvery query filtered by tenant_idVerified

Data protection

ControlImplementationStatus
Encryption at restAzure PostgreSQL AES-256Active
Encryption in transitTLS 1.3Active
Password hashingbcrypt (12 rounds)Active
Parameterized SQL154 queries, 0 concatenationVerified
SecretsAzure Key VaultActive
Audit trailAppend-only, ALCOA+ compliantActive

Content Security Policy

Strict CSP with per-request nonces on scripts (no unsafe-inline). Full set of security headers returned on every response: HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy, Cross-Origin-Opener-Policy, Cross-Origin-Resource-Policy.

Testing & validation

Independent penetration testing on 17–18 April 2026 (10 OWASP categories, 36 payloads): 0 vulnerabilities.Functional security testing on 11 April 2026 covering 1,890+ API calls across 270 appointments: 0 failures.Annual third-party pentest scheduled and SOC 2 Type II audit in progress.

Compliance

  • EU GMP Annex 11 — Data integrity (ALCOA+), append-only audit trail, electronic records, access control, validated
  • 21 CFR Part 11 — Electronic records, audit trail, attribution, seal chain of custody
  • GDPR — Data portability (JSON + CSV), DSAR workflow, consent tracking, EU/EEA-only residency
  • SOC 2 Type II — Audit in progress

Documents & templates

Responsible disclosure

We welcome reports from security researchers. Email admin@yardtwin.comwith a description of the finding and steps to reproduce. We acknowledge receipt within 2 business days and aim to patch critical issues within 7 days. Please do not publicly disclose vulnerabilities before we have had a chance to remediate.

Last updated: April 2026 · yardtwin.com

Hi there! Start your free trial in 2 minutes — I'll help you set everything up!