Encryption
- In transit — all traffic between your browser and the Service is encrypted using TLS (HTTPS).
- At rest — data stored in our database and backups is encrypted at rest by our infrastructure provider.
Authentication
- Passwords are never stored in plain text — only as salted, hashed values.
- Sign-in and session management are handled by a dedicated authentication library.
- Email verification is required to confirm account ownership.
- Sessions can be revoked by signing out.
Infrastructure and hosting
The Service is hosted on Amazon Web Services (AWS), eu-central-1 region (Frankfurt, Germany). We rely on managed, industry-standard cloud infrastructure with physical and network security maintained by our provider. Your data stays within the European Union.
Access control and data isolation
- Access to production systems is restricted on a least-privilege basis.
- Within the product, time-off and profile data is scoped to your team and visible only to the relevant members.
Backups and reliability
We maintain regular backups so data can be restored in the event of an incident. Server activity is logged to help us detect and investigate suspicious behaviour.
Sub-processors
We use a small set of trusted sub-processors to run the Service. They are listed, along with their purpose and location, in our Privacy Policy.
Responsible disclosure
We welcome reports from security researchers. If you believe you have found a vulnerability, please email support@flexi-day.com with the details and steps to reproduce. Please:
- give us a reasonable opportunity to investigate and fix the issue before disclosing it;
- avoid accessing or modifying other users’ data, and avoid service disruption;
- act in good faith and within the law.
We will acknowledge your report and keep you informed of our progress.
Contact
Security questions? Reach us at support@flexi-day.com.