Skip to main content

Security

Last updated: 2026-07-03

Security and data protection are built into how Devya Solutions designs, ships, and operates software. This page summarises the measures that protect the data of our clients and their users — written for procurement, vendor-assessment, and due-diligence reviews. Questions or security questionnaires: contact@devya.dev.

Our Security Practices

Encryption in transit

All traffic to our websites, APIs, and admin systems is served over HTTPS/TLS, with HTTP Strict Transport Security (HSTS) enabled. There are no unencrypted endpoints.

Password security

Account passwords are hashed with argon2id, a modern memory-hard algorithm resistant to GPU cracking. Passwords are never stored or logged in plaintext.

Access control

Internal and administrative systems enforce role-based access control (RBAC) on the principle of least privilege. Accounts are locked out after repeated failed sign-in attempts.

Audit logging

Administrative and authentication events — sign-ins, permission changes, data exports, deletions — are recorded in an audit trail that can be reviewed after the fact.

Data location

EU data location is available where applicable for the client systems we host and operate. Our infrastructure runs on Cloudflare, Vercel, and EU-region VPS hosting (Hostinger).

Encryption at rest

Production data is stored on managed, encrypted disks provided by our hosting infrastructure.

Backups

Automated daily backups run with a defined retention window, and restore procedures are documented so data can be recovered after failure or error.

Privacy by default

No analytics or marketing trackers load before consent. Data-subject requests (export and erasure) are supported by dedicated endpoints, and configurable retention periods are enforced automatically.

Incident response

We maintain a documented breach-response runbook. Where required by the GDPR, we notify the competent supervisory authority within 72 hours and affected users without undue delay.

Responsible Disclosure

If you believe you have found a security vulnerability in any Devya system, please report it to contact@devya.dev with enough detail to reproduce the issue. We will acknowledge your report promptly, keep you informed while we investigate, and will not pursue legal action against good-faith security research. We ask that you give us reasonable time to remediate before any public disclosure and that you avoid accessing or modifying data that is not yours.

Related Policies

Privacy Policy Cookie Policy