Trust
Trust & Security
How we protect your data and run the platform responsibly.
Last updated: 28 July 2026
Brand owners and law firms trust HAKKIU with sensitive enforcement data. This page summarizes the technical and organizational measures we use to protect it. It also serves as Annex B (security measures) to our Data Processing Agreement.
Hosting and data location
- Core infrastructure is hosted in the EEA (Germany).
- We use Cloudflare for CDN, DNS and edge protection.
- A current list of infrastructure providers is on our Sub-processors page.
Encryption
- All traffic is encrypted in transit using TLS (HTTPS), with HSTS enforced.
- Data is encrypted at rest by our hosting and database providers.
Access control
- Least-privilege access; administrative access is restricted and logged.
- Customer data is logically segregated per organization (multi-tenant isolation).
- Authentication is handled by a dedicated identity provider; customer logins are provisioned by staff.
Application security
- Security headers (CSP, X-Content-Type-Options, Referrer-Policy, Permissions-Policy) and framing protection.
- Rate limiting and input validation on public endpoints.
- Internal service endpoints are protected by shared secrets and network controls.
Sub-processor vetting
We engage reputable sub-processors under GDPR-consistent data-protection terms and remain responsible for their performance. See Sub-processors.
Backups and resilience
- Databases are backed up on a regular schedule.
- We monitor availability and respond to operational incidents.
Incident response
We maintain an incident-response process and will notify affected customers of a personal-data breach without undue delay, consistent with the GDPR and our DPA.
Compliance
HAKKIU processes personal data in line with the GDPR. As we grow we intend to pursue recognized certifications (such as SOC 2 / ISO 27001); this page will be updated when they are in place.
Responsible disclosure
If you believe you've found a security vulnerability, please report it to security@hakkiu.com. Please give us a reasonable opportunity to investigate and remediate before any public disclosure. We appreciate the security community's help and will not pursue good-faith research conducted under this policy.
Request our DPA or security documentation
Procurement or vendor-review team? Email legal@hakkiu.com to request a signed DPA or additional security documentation.