Information Security Overview
DeepTech sp. z o.o. · Version 1.2 — pending management approval · October 2026
| Field | Value |
|---|---|
| Owner | DeepTech sp. z o.o. — CTO (system owner); approved by the Management Board |
| Version | 1.2 |
| Status | Pending management approval (Management Board of DeepTech sp. z o.o.) |
| Effective | On approval — October 2026 (supersedes v1.1, v1.0 and Draft v0.9) |
| Review | Every 12 months or after a material change |
| Classification | Public |
Public summary of the security controls protecting the Audomate platform, hosted on Google Cloud in EEA regions only (europe-west1 Belgium — primary; europe-west3 Germany — disaster recovery; europe-west4 Netherlands — dual-region object storage). Detailed policies (Information Security Policy, risk management, BCP) are internal and available to clients under NDA.
1. Network security
- TLS 1.3 on all external connections; TLS 1.2 enforced as minimum — no unencrypted channels.
- Mutual TLS (mTLS) between internal Cloud Run services via Google Cloud Service Mesh.
- Google Cloud Armor Web Application Firewall in front of the API gateway — OWASP Top-10 protection, adaptive DDoS mitigation; rate limiting at the API gateway (FastAPI).
- Data layer (Cloud SQL database, Cloud Storage, Memorystore cache) on private networking (VPC with Private Service Connect) — no public IP addresses.
2. Identity and access
- SSO via SAML 2.0 / OIDC through an EU-region identity provider (Auth0, eu.auth0.com); federation with the client's own enterprise identity provider; MFA mandatory.
- JWT access tokens with 15-minute TTL; 7-day refresh tokens with rotation; identity-provider anomaly detection.
- Role-based access control at application level (Auditor, Vendor Manager, Compliance Manager, IT Admin); PostgreSQL row-level security as an independent second enforcement layer — cross-tenant access is structurally impossible.
- Secrets in Google Secret Manager (customer-managed keys) with access auditing; rotation every 90 days. Internal staff access to production follows least privilege and is logged.
3. Data protection
- Encryption at rest: AES-256 across the database (customer-managed keys via Cloud KMS), object storage (server-side encryption) and vector indexes; key rotation every 90 days with alerts on rotation failure.
- Automated backups and point-in-time recovery on the primary database with a 7-day retention window (Cloud SQL automated backups 7 days + PITR 7 days); object storage replicated dual-region within the EEA. RPO 1–4 h, RTO 4–8 h by plan tier; last restore test: 1 September 2026, next due by 1 March 2027 (see the Business Continuity & DR Summary).
- Hard deletion on request: a purge pipeline removes vector, relational and object-storage records in one operation.
4. AI-layer security
- LLM inference and embeddings through the OpenAI API with EU data residency (EU-region project, endpoint eu.api.openai.com; contracting entity OpenAI Ireland Ltd) under Zero Data Retention terms approved on the project; no client content used for training. No other cloud AI provider is used.
- Prompt-injection detection and input sanitisation at the API gateway before any model call; per-tenant session isolation; per-tenant token budgets with utilisation alerts (protection against denial-of-wallet).
5. Logging and monitoring
- Immutable, hash-chained audit log of every user action, AI verdict and human override.
- Centralised monitoring (Cloud Monitoring + Cloud Logging) with error-rate, latency and LLM dashboards; alerts routed to the on-call engineer through PagerDuty; syslog (RFC 5424) / REST forwarding to the client's SIEM available.
6. Incident management
Severity-based response with on-call escalation via PagerDuty: critical incidents — tenant isolation, CTO/CEO escalation within 15 minutes, affected-client notification within 30 minutes (Enterprise) or 24 hours (Standard/Pro); personal-data breaches notified per GDPR art. 33 within 72 hours to the supervisory authority (PUODO) and within 24 hours to affected clients as controllers; personal-data aspects are coordinated by the Data Protection Coordinator (Kacper Raubo, kacper.raubo@deeptech.pl). See the Incident Response & Breach Notification Summary.
7. Certifications
Hosting layer (Google Cloud): ISO 27001, SOC 2, CSA STAR — inherited infrastructure controls. DeepTech organisation: ISO 27001 in preparation (target: Q1 2027); independent penetration test planned for Q1 2027 — vendor selection in progress. Reports will be published in the Trust Center when complete.
8. Vulnerability disclosure
We welcome reports from security researchers and clients about vulnerabilities in audomate.eu, app.audomate.eu or our APIs (coordinated vulnerability disclosure, in line with ENISA guidance on Regulation 2024/2690, Annex section 6.10).
- Report to security@audomate.eu (mailbox live); our contact details and policy are also published in machine-readable form at audomate.eu/.well-known/security.txt (RFC 9116).
- We acknowledge receipt within 5 business days, keep you informed about progress and tell you when the issue is fixed; vulnerabilities are triaged by the CTO using CVSS severity and remediated under the patch SLA in section 7.
- Please act in good faith: do not access, modify or delete data that is not yours, do not disrupt the service, and give us reasonable time to fix the issue before public disclosure. We will not pursue legal action against research that respects these rules.
Document control
| Version | Date | Author | Approved by | Changes |
|---|---|---|---|---|
| 0.9 | September 2026 | DeepTech (CTO / CEO) | — (working draft, not adopted) | Working draft published for transparency; items marked "to confirm". |
| 1.0 | October 2026 | DeepTech (CEO / CTO) | — (superseded by 1.1) | Changes after the GDPR (RODO) / NIS2 audit of 7–8 October 2026: section 7 "pending" replaced by a proposed secure-development baseline (flagged for CTO confirmation); new section 9 "Vulnerability disclosure" (security@audomate.eu, security.txt); PagerDuty, Google Cloud Service Mesh, Cloud Armor, Private Service Connect and Auth0 EU specified from Annex #2; section 8 kept with date confirmation flag. |
| 1.1 | 10 October 2026 | DeepTech (CEO / CTO / data protection coordinator) | Management Board — pending | Updates after Management Board decisions of 10 Oct 2026: AI layer corrected to OpenAI Ireland Ltd (OpenAI API, EU data residency, Zero Data Retention) — no other cloud AI provider used; backup window 7 days and last restore test (1 September 2026) added to section 3; security@audomate.eu confirmed live; Data Protection Coordinator named (Kacper Raubo). |
| 1.2 | 11 October 2026 | DeepTech (CEO / CTO / data protection coordinator) | Management Board — pending | Dates confirmed by the Management Board on 11 Oct 2026: ISO 27001 certification target Q1 2027 (was H1 2027) and penetration test Q1 2027. Secure-development section removed pending CTO confirmation of current practice; sections renumbered (Certifications 7, Vulnerability disclosure 8). |