Trust

Trust & Security

How we protect your data and run the platform responsibly.

Last updated: 28 July 2026


Brand owners and law firms trust HAKKIU with sensitive enforcement data. This page summarizes the technical and organizational measures we use to protect it. It also serves as Annex B (security measures) to our Data Processing Agreement.

Hosting and data location

  • Core infrastructure is hosted in the EEA (Germany).
  • We use Cloudflare for CDN, DNS and edge protection.
  • A current list of infrastructure providers is on our Sub-processors page.

Encryption

  • All traffic is encrypted in transit using TLS (HTTPS), with HSTS enforced.
  • Data is encrypted at rest by our hosting and database providers.

Access control

  • Least-privilege access; administrative access is restricted and logged.
  • Customer data is logically segregated per organization (multi-tenant isolation).
  • Authentication is handled by a dedicated identity provider; customer logins are provisioned by staff.

Application security

  • Security headers (CSP, X-Content-Type-Options, Referrer-Policy, Permissions-Policy) and framing protection.
  • Rate limiting and input validation on public endpoints.
  • Internal service endpoints are protected by shared secrets and network controls.

Sub-processor vetting

We engage reputable sub-processors under GDPR-consistent data-protection terms and remain responsible for their performance. See Sub-processors.

Backups and resilience

  • Databases are backed up on a regular schedule.
  • We monitor availability and respond to operational incidents.

Incident response

We maintain an incident-response process and will notify affected customers of a personal-data breach without undue delay, consistent with the GDPR and our DPA.

Compliance

HAKKIU processes personal data in line with the GDPR. As we grow we intend to pursue recognized certifications (such as SOC 2 / ISO 27001); this page will be updated when they are in place.

Responsible disclosure

If you believe you've found a security vulnerability, please report it to security@hakkiu.com. Please give us a reasonable opportunity to investigate and remediate before any public disclosure. We appreciate the security community's help and will not pursue good-faith research conducted under this policy.

Request our DPA or security documentation

Procurement or vendor-review team? Email legal@hakkiu.com to request a signed DPA or additional security documentation.

Note: This document is provided for transparency and is not legal advice. HAKKIU is an EU-established company; specific company registration details are set out in our Legal Notice. If you have questions, contact us at legal@hakkiu.com.