Trust Center

Introduction

URIports B.V. provides a unified platform for monitoring the security, health, and configuration of domains. Covering email security, website security, and domain and infrastructure monitoring, it collects and analyzes reports from mail servers, browsers, and other internet-facing systems to help organizations identify configuration issues, policy violations, certificate problems, authentication failures, and other security-relevant events. For a complete overview of our platform and features, please visit our website.

URIports is operated by a team of security professionals and software engineers based in the Netherlands and subject to European Union data protection laws. Security, privacy, and operational resilience are core principles that guide both the design of our platform and our day-to-day operations.

Privacy and data minimization are built into URIports from the ground up. We collect as little personal data as possible, use it only to deliver the service, and never sell or repurpose it. Your data always remains yours, and we actively remove or anonymize anything that may contain personal data.

This Trust Center is designed to support vendor risk assessments, security reviews, compliance evaluations, and due diligence processes. It provides transparency into our security controls, data handling practices, operational procedures, and compliance commitments.


Privacy and Data Handling

Handling of Potential Personal Data

While the platform is not designed to process personal data, certain report types (such as DMARC failure reports) may incidentally contain sensitive information.

URIports applies strict data minimization:

  • Message bodies are removed
  • Personal data is stripped from headers where possible
  • URL query parameters are removed from reports
  • Message bodies and headers are only retained if the customer provides a PGP public key for encryption; otherwise this data is stripped

This ensures that only the customer can access sensitive report content when required.

Data Retention

Customer data is retained only for the duration of the active subscription and in accordance with the configured retention period.

  • Data is retained for up to 90 days, depending on the retention settings of the subscription
  • Data is automatically deleted after the applicable retention period
  • Upon termination, customer data is removed from production and failover systems immediately; residual copies in encrypted backups expire within 14 days
  • No long-term storage or reuse of customer data takes place beyond service delivery requirements

This approach ensures strong data minimization and controlled data exposure.


URIports provides the following documents:

URIports acts as data processor (or sub-processor where applicable) under GDPR. The customer acts as data controller. We process data solely to deliver the service and provide reasonable assistance for your GDPR compliance obligations.


Certifications and Compliance

URIports does not currently hold formal third-party certifications such as ISO 27001 or SOC 2, and there are no concrete plans to pursue these in the near term.

Instead, our security posture is built around:

  • A privately operated, GDPR-compliant infrastructure based in the Netherlands
  • A deliberately minimal scope, by design we do not process business or end-user personal data beyond what is technically necessary
  • Internal security practices (access control, encryption, monitoring, and change management) that align with the spirit of common frameworks, even without formal certification

Infrastructure and Hosting

URIports runs on privately owned servers in a GDPR-compliant datacenter in the Netherlands. We do not rely on public cloud providers for any core services, giving us full infrastructure control and a predictable security posture.


Security Architecture

Network Security

  • Hardware firewalls
  • Intrusion detection systems
  • DDoS protection

Encryption

  • All traffic secured via TLS 1.2 or higher (TLS 1.3 preferred), with HSTS
  • Email transport secured with DANE, SPF, DKIM, and DMARC
  • Account passwords hashed with bcrypt
  • Backups encrypted with AES-256-CTR and integrity-verified with HMAC-SHA256; the per-backup key is encrypted with an RSA public key (envelope encryption)
  • Sensitive report data is removed on ingest, or encrypted with the customer's own PGP key

Production servers do not use full-disk encryption. This is a deliberate, risk-based choice: privately owned hardware in an access-controlled Dutch datacenter, minimal and short-lived data (90-day maximum retention), and fully encrypted backups.

Key Management

  • Keys and secrets are stored in an encrypted vault, protected with hardware security keys (YubiKey)
  • Backup decryption keys are stored offline, separate from the backup infrastructure
  • Keys are rotated on personnel changes or suspected compromise

Access Control

  • Role-based access control (RBAC) is applied across all systems
  • Principle of least privilege enforced
  • Accounts, access rights, and keys are periodically reviewed
  • Multi-Factor Authentication (MFA) required for all privileged access
  • Strong password policies enforced for all accounts
  • Rate limiting applied to authentication endpoints
  • Only company-managed, encrypted devices are permitted

Development and Change Management

  • All changes require peer review before deployment
  • Releases follow a controlled change management process
  • Secure coding practices are applied throughout development
  • Automated vulnerability scanning is performed on all dependencies

Monitoring and Incident Management

Logging

Security-relevant events are logged across the platform and infrastructure, including:

  • Authentication events (logins, failed attempts, MFA events)
  • Administrative and privileged actions
  • System and network events

The platform holds minimal personal data by design; log retention is set in proportion to this risk profile. Details are available on request.

Monitoring and Alerting

Security-relevant events, service failures, and anomalies automatically alert our on-call engineers, 24 hours a day, 7 days a week.

Incident Response

Alerts reach our engineers directly, without a tiered support queue. Incidents are triaged immediately, mitigated, and documented. Affected customers are informed, and personal data breaches are notified without undue delay in accordance with our Data Processing Agreement.


Backup and Recovery

Our recovery strategy is layered:

  • Failover: fully synchronized standby servers take over if production fails
  • Backups: daily encrypted backups (see Security Architecture) on separate hardware and offsite

Restore verification is a manual, offline procedure so the backup decryption key never needs to be stored online.


Vulnerability and Patch Management

  • Security patches applied quickly and regularly
  • Priority given to critical vulnerabilities
  • Continuous monitoring of dependencies
  • Ongoing improvement of security posture

Security Testing

Security testing relies on continuous automated vulnerability and dependency scanning and mandatory peer review of all code changes. We do not commission recurring external penetration tests; we consider this proportionate to our risk profile.

Responsible Disclosure

We welcome good-faith vulnerability reports via our security.txt. Impactful reports are credited in our Hall of Fame.


Endpoint Security

All staff use company-managed devices with full disk encryption and endpoint protection. No personal or unmanaged devices are used to access production systems.


Third-Party Risk

We use no subprocessors. Our only external service provider is Paddle (payment processing as Merchant of Record; Paddle acts as an independent data controller for checkout data). Core infrastructure is entirely self-managed, which significantly reduces supply chain exposure.


Service Levels and Availability

  • URIports does not currently offer a formal Service Level Agreement with guaranteed uptime percentages
  • We make commercially reasonable efforts to keep our Services operational 24 hours a day, seven days a week
  • This is consistent with the Service Level section of our Terms of Service

Business Continuity

Fully synchronized standby servers provide rapid failover, and daily encrypted backups (separate hardware and offsite) support a recovery point of up to 24 hours.

Report data is ephemeral by design: retained for at most 90 days and continuously replaced by incoming reports. Even after worst-case data loss, monitoring resumes automatically as new reports arrive.


Applicability of Standard Security Requirements

URIports processes technical reporting data, and no business or end-user personal data beyond what is technically necessary. As a result, some controls in standard security questionnaires designed for PII-heavy environments may not directly apply. We are happy to clarify our position on any specific requirement on request.


Contact

We hope this overview gives you a clear picture of how URIports approaches security, privacy, and compliance. If you have additional questions, need more detail on any of the topics above, or require information for your own vendor risk assessment, please reach out to our helpdesk.