Trust Center
Introduction
URIports B.V. provides a unified platform for monitoring the security, health, and configuration of domains. Covering email security, website security, and domain and infrastructure monitoring, it collects and analyzes reports from mail servers, browsers, and other internet-facing systems to help organizations identify configuration issues, policy violations, certificate problems, authentication failures, and other security-relevant events. For a complete overview of our platform and features, please visit our website.
URIports is operated by a team of security professionals and software engineers based in the Netherlands and subject to European Union data protection laws. Security, privacy, and operational resilience are core principles that guide both the design of our platform and our day-to-day operations.
Privacy and data minimization are built into URIports from the ground up. We collect as little personal data as possible, use it only to deliver the service, and never sell or repurpose it. Your data always remains yours, and we actively remove or anonymize anything that may contain personal data.
This Trust Center is designed to support vendor risk assessments, security reviews, compliance evaluations, and due diligence processes. It provides transparency into our security controls, data handling practices, operational procedures, and compliance commitments.
Privacy and Data Handling
Handling of Potential Personal Data
While the platform is not designed to process personal data, certain report types (such as DMARC failure reports) may incidentally contain sensitive information.
URIports applies strict data minimization:
- Message bodies are removed
- Personal data is stripped from headers where possible
- URL query parameters are removed from reports
- Message bodies and headers are only retained if the customer provides a PGP public key for encryption; otherwise this data is stripped
This ensures that only the customer can access sensitive report content when required.
Data Retention
Customer data is retained only for the duration of the active subscription and in accordance with the configured retention period.
- Data is retained for up to 90 days, depending on the retention settings of the subscription
- Data is automatically deleted after the applicable retention period
- Upon termination, customer data is removed from production and failover systems immediately; residual copies in encrypted backups expire within 14 days
- No long-term storage or reuse of customer data takes place beyond service delivery requirements
This approach ensures strong data minimization and controlled data exposure.
Legal and GDPR Position
URIports provides the following documents:
- Terms of Service: https://www.uriports.com/terms
- Privacy Policy: https://www.uriports.com/privacy
- Data Processing Agreement (DPA): https://www.uriports.com/dpa
URIports acts as data processor (or sub-processor where applicable) under GDPR. The customer acts as data controller. We process data solely to deliver the service and provide reasonable assistance for your GDPR compliance obligations.
Certifications and Compliance
URIports does not currently hold formal third-party certifications such as ISO 27001 or SOC 2, and there are no concrete plans to pursue these in the near term.
Instead, our security posture is built around:
- A privately operated, GDPR-compliant infrastructure based in the Netherlands
- A deliberately minimal scope, by design we do not process business or end-user personal data beyond what is technically necessary
- Internal security practices (access control, encryption, monitoring, and change management) that align with the spirit of common frameworks, even without formal certification
Infrastructure and Hosting
URIports runs on privately owned servers in a GDPR-compliant datacenter in the Netherlands. We do not rely on public cloud providers for any core services, giving us full infrastructure control and a predictable security posture.
Security Architecture
Network Security
- Hardware firewalls
- Intrusion detection systems
- DDoS protection
Encryption
- All traffic secured via TLS 1.2 or higher (TLS 1.3 preferred), with HSTS
- Email transport secured with DANE, SPF, DKIM, and DMARC
- Account passwords hashed with bcrypt
- Backups encrypted with AES-256-CTR and integrity-verified with HMAC-SHA256; the per-backup key is encrypted with an RSA public key (envelope encryption)
- Sensitive report data is removed on ingest, or encrypted with the customer's own PGP key
Production servers do not use full-disk encryption. This is a deliberate, risk-based choice: privately owned hardware in an access-controlled Dutch datacenter, minimal and short-lived data (90-day maximum retention), and fully encrypted backups.
Key Management
- Keys and secrets are stored in an encrypted vault, protected with hardware security keys (YubiKey)
- Backup decryption keys are stored offline, separate from the backup infrastructure
- Keys are rotated on personnel changes or suspected compromise
Access Control
- Role-based access control (RBAC) is applied across all systems
- Principle of least privilege enforced
- Accounts, access rights, and keys are periodically reviewed
- Multi-Factor Authentication (MFA) required for all privileged access
- Strong password policies enforced for all accounts
- Rate limiting applied to authentication endpoints
- Only company-managed, encrypted devices are permitted
Development and Change Management
- All changes require peer review before deployment
- Releases follow a controlled change management process
- Secure coding practices are applied throughout development
- Automated vulnerability scanning is performed on all dependencies
Monitoring and Incident Management
Logging
Security-relevant events are logged across the platform and infrastructure, including:
- Authentication events (logins, failed attempts, MFA events)
- Administrative and privileged actions
- System and network events
The platform holds minimal personal data by design; log retention is set in proportion to this risk profile. Details are available on request.
Monitoring and Alerting
Security-relevant events, service failures, and anomalies automatically alert our on-call engineers, 24 hours a day, 7 days a week.
Incident Response
Alerts reach our engineers directly, without a tiered support queue. Incidents are triaged immediately, mitigated, and documented. Affected customers are informed, and personal data breaches are notified without undue delay in accordance with our Data Processing Agreement.
Backup and Recovery
Our recovery strategy is layered:
- Failover: fully synchronized standby servers take over if production fails
- Backups: daily encrypted backups (see Security Architecture) on separate hardware and offsite
Restore verification is a manual, offline procedure so the backup decryption key never needs to be stored online.
Vulnerability and Patch Management
- Security patches applied quickly and regularly
- Priority given to critical vulnerabilities
- Continuous monitoring of dependencies
- Ongoing improvement of security posture
Security Testing
Security testing relies on continuous automated vulnerability and dependency scanning and mandatory peer review of all code changes. We do not commission recurring external penetration tests; we consider this proportionate to our risk profile.
Responsible Disclosure
We welcome good-faith vulnerability reports via our security.txt. Impactful reports are credited in our Hall of Fame.
Endpoint Security
All staff use company-managed devices with full disk encryption and endpoint protection. No personal or unmanaged devices are used to access production systems.
Third-Party Risk
We use no subprocessors. Our only external service provider is Paddle (payment processing as Merchant of Record; Paddle acts as an independent data controller for checkout data). Core infrastructure is entirely self-managed, which significantly reduces supply chain exposure.
Service Levels and Availability
- URIports does not currently offer a formal Service Level Agreement with guaranteed uptime percentages
- We make commercially reasonable efforts to keep our Services operational 24 hours a day, seven days a week
- This is consistent with the Service Level section of our Terms of Service
Business Continuity
Fully synchronized standby servers provide rapid failover, and daily encrypted backups (separate hardware and offsite) support a recovery point of up to 24 hours.
Report data is ephemeral by design: retained for at most 90 days and continuously replaced by incoming reports. Even after worst-case data loss, monitoring resumes automatically as new reports arrive.
Applicability of Standard Security Requirements
URIports processes technical reporting data, and no business or end-user personal data beyond what is technically necessary. As a result, some controls in standard security questionnaires designed for PII-heavy environments may not directly apply. We are happy to clarify our position on any specific requirement on request.
Contact
We hope this overview gives you a clear picture of how URIports approaches security, privacy, and compliance. If you have additional questions, need more detail on any of the topics above, or require information for your own vendor risk assessment, please reach out to our helpdesk.