We are fully compliant with The European Union’s General Data Protection Regulation (GDPR). You can read our privacy policy here.
All servers have security updates automatically applied. We routinely upgrade our operating systems as new versions are released.
All Services are available over TLS, which is enforced for our website and account system, and personal data is encrypted in transit between our hosting locations.
Services are hosted in Germany and the United States. International transfers are safeguarded under the UK-EU adequacy decision, Standard Contractual Clauses, and the UK International Data Transfer Addendum. Full detail is available in our Data Processing Agreement.
Request logs are retained for up to 45 days. See our Privacy Policy and Data Processing Agreement for full retention schedules.
We use Heroku (PaaS) to manage backups for customer data in our billing system. For other systems, we create our own backups and store them with a second cloud service provider. This allows us to recover our infrastructure even if there’s a total failure with our primary service provider. See our Sub-processors page for the specific providers we use.
You provide your payment card information to our payment partner (Stripe) and we do not store the card number ourselves. We do store the last four digits of the card number, to provide you this information when you are managing your payments, and the card expiry so that we can notify you when you need to update your card information.
Access to production systems requires individual named accounts and SSH key authentication, and two-factor authentication is enforced on third-party services we rely on. All employees and contractors are required to use password managers, and access follows the principle of least privilege. Access is revoked immediately when a staff member’s engagement ends.
If we identify a security incident affecting your data, we will notify the contact details on your account within 72 hours. Unsuccessful attempts to access our systems — such as port scans or failed authentication attempts — are monitored but are not treated as security incidents in themselves.
We gratefully receive reports of security issues. However, we don’t offer a bug bounty.
If you are the first to identify a genuine problem we will provide acknowledgement. We reserve the right to decide on this issue.
Please email: security (at) thunderforest (dot) com
Please do not …