Assoluto
Public demo This is a public demo with fictional data. Anything you change is reset every night. Create your own portal

Security

How we protect your data

What the service does today, in plain words. We list what is in place, not plans.

Every supplier and every client sees only their own

Each supplier's portal is a separate tenant. PostgreSQL Row-Level Security filters every query by tenant inside the database, and the application connects with a database role that cannot switch these policies off — so even a bug in the application cannot return another supplier's orders.

Within a portal, each client contact sees only the orders, drawings and material of their own company.

Accounts and sign-in

  • Passwords are stored only as Argon2id hashes — never in readable form.
  • Sign-in, signup, password reset and the contact form are rate-limited against brute force.
  • Password-reset and invitation links work only once.
  • Changing a password signs out every existing session.
  • Session cookies are HttpOnly and SameSite=Lax, and sent only over HTTPS in production.
  • Every form is protected against cross-site request forgery (CSRF).

Hosting and backups

  • The application, the database and uploaded files are hosted by Hetzner Online GmbH in Germany (EU) — a server for the application and database, Hetzner Object Storage for drawings and attachments.
  • All traffic is encrypted with HTTPS (HSTS enabled); pages are served with a strict Content-Security-Policy.
  • The database is backed up daily and encrypted; copies are kept 14 days on the server and 180 days in a second Hetzner location. Uploaded files are copied there too.
  • Emails are delivered through Brevo (France, EU). Card payments, when enabled, are processed by Stripe — we never see card numbers.

Who can see your data

  • You decide who in your company and which of your clients gets an account.
  • Our own operator account cannot browse your portal. Support access is granted to a specific portal only when needed, and the grant is recorded in that portal's audit log.
  • Administrative actions inside your portal are recorded in an audit trail.

Your data stays yours

  • Administrators can export all portal data at any time — orders and customers as CSV, attachments as ZIP.
  • Every user can download their personal data and delete their own account from their profile (GDPR Art. 15, 17 and 20).
  • The source code is open (AGPL-3.0), so anyone can check how it works.

The full list of subprocessors and retention periods is in the Privacy Policy. Our processing of your clients' data is governed by the Data Processing Agreement.

Who is behind Assoluto

Assoluto is operated by Václav Mudra, Company ID (IČO) 09989978, Lidická 2020/2, 405 02 Děčín.

Write to team@assoluto.eu — we reply within 1 working day. Imprint · Security