Security

GDPR

We are fully compliant with The European Union’s General Data Protection Regulation (GDPR). You can read our privacy policy here.

Infrastructure

All servers have security updates automatically applied. We routinely upgrade our operating systems as new versions are released.

All Services are available over TLS, which is enforced for our website and account system, and personal data is encrypted in transit between our hosting locations.

Data Hosting

Services are hosted in Germany and the United States. International transfers are safeguarded under the UK-EU adequacy decision, Standard Contractual Clauses, and the UK International Data Transfer Addendum. Full detail is available in our Data Processing Agreement.

Data Retention

Request logs are retained for up to 45 days. See our Privacy Policy and Data Processing Agreement for full retention schedules.

Backups

We use Heroku (PaaS) to manage backups for customer data in our billing system. For other systems, we create our own backups and store them with a second cloud service provider. This allows us to recover our infrastructure even if there’s a total failure with our primary service provider. See our Sub-processors page for the specific providers we use.

Credit card data

You provide your payment card information to our payment partner (Stripe) and we do not store the card number ourselves. We do store the last four digits of the card number, to provide you this information when you are managing your payments, and the card expiry so that we can notify you when you need to update your card information.

Personnel Access Controls

Access to production systems requires individual named accounts and SSH key authentication, and two-factor authentication is enforced on third-party services we rely on. All employees and contractors are required to use password managers, and access follows the principle of least privilege. Access is revoked immediately when a staff member’s engagement ends.

Incident Response

If we identify a security incident affecting your data, we will notify the contact details on your account within 72 hours. Unsuccessful attempts to access our systems — such as port scans or failed authentication attempts — are monitored but are not treated as security incidents in themselves.

Reporting of security issues

We gratefully receive reports of security issues. However, we don’t offer a bug bounty.

If you are the first to identify a genuine problem we will provide acknowledgement. We reserve the right to decide on this issue.

Please email: security (at) thunderforest (dot) com

Please do not …

  • … interrupt the normal working of any of our products or services
  • … identify problems on third-party services that we use
  • … send us general reports – please offer specifics
  • … make this information publicly available until we’ve had a chance to fix the bug

Security Acknowledgements

  • September 2023 - Taha Diwan - Unintended access to server performance information
  • March 2025 - Aura - TLS 1.0 available on bare root domain HTTP redirect
  • June 2025 - Mahmoud Omar - Path traversal technique allowing access to server performance information