This document describes our security policy. We cannot guarantee that no leak will ever happen, but we do our best to keep your data safe.
How we develop secure software
- We use code reviews to detect vulnerabilities before merging and delivering to customers,
- We ensure that we check for permissions for any resources we have, and we regularly review those permissions,
- We use Git to manage changes, so that any code that goes to production is easily auditable.
How we keep our communications secure
We make our best to use state-of-the-art techniques to keep the data safe:
- We use SSH keys to access our servers,
- We use HTTPS and SSL certificates to communicate between us and with you.
- We don't transfer data in clear-text over the network.
How we keep the data secure
Once again, we make our best to use state-of-the-art techniques to keep the data safe:
- We host data using Digital Ocean and Amazon AWS,
- The hard drives of our personal computers are encrypted (for example with Apple's FileVault 2),
- Our personal backup drives are encrypted (for example with Apple's FileVault 2 / Time Machine).
Where we host your data
How to handle a vulnerability
If you notice a vulnerability, please submit it at https://playsql.atlassian.net/servicedesk/customer/portals and:
- We will investigate as soon as we can and write an internal report,
- If we confirm the vulnerability, we will notify Atlassian,
- If a breach allowed access or alteration of customer data, we also notify our GDPR authorities within 72hrs (namely CNIL, for France),
- If a breach allowed access or alteration of customer data by an external person, we also notify those customers directly.
- If a breach only allowed two users of the same customer to view/edit data they were not permitted to (permission violation), we choose whether we only notify customers through the release notes when delivering the new version, or whether we directly contact customers.
Please send notifications to https://playsql.atlassian.net/servicedesk/customer/portals (In case this portal meets a breach, we are also available by email at email@example.com).