Security
Recipes and specifications are among the most confidential information a food company has. This page describes how Eclarion protects them. Everything on this page can be checked.
Where your data lives
The platform, the database and your files run on our own servers at Hetzner in Germany (Falkenstein). The backups deliberately sit in a different location, Finland (Helsinki), also in the EU. Your data lives in the EU. For email, support, translation and AI assistance we work with specialised services, also outside the EU and then under a valid legal framework. All parties are listed with function and location on our sub-processors page.
The database sits on an encrypted disk and is reachable only over a private network. The backups are encrypted and all traffic runs over TLS.
Your data stays yours. You can export everything yourself at any time. After cancellation your environment stays available for three months to download; after that we delete your data permanently and copies disappear from the backups within 45 days.
Who can access it
- Every user has a personal account. Two-factor authentication is available to every user and can be made mandatory per organisation. Single sign-on via SAML (including Microsoft Entra ID) can be enforced as well, so your own organisation's access and MFA policy applies.
- Permissions are configurable per user and per module (Viewer, Editor, Administrator).
- Customer environments are strictly separated. Every database query is bound to your environment and guarded by two independent automated controls.
- Changes are recorded in an audit trail that cannot be modified after the fact.
- Access by Eclarion itself is limited to what is needed for support and operations, personal and with two-factor authentication. Whatever Eclarion changes in your environment is in your audit trail, by name.
How we build
- Every change to the code is scanned automatically for known vulnerabilities. Only a change that passes the scan without findings can be accepted. That condition is enforced technically.
- Every release is checked for known vulnerabilities in all software libraries it uses (server and browser), for accidentally included passwords or keys, and for operating-system vulnerabilities. With findings in libraries or keys, no release is built.
- The application is protected against the common web attacks, such as cross-site scripting and SQL injection, and runs with an enforced Content Security Policy.
- A password that appears in a known data breach is refused. Anyone who already has such a password is warned at login. The check happens without the password ever leaving the server.
- Every release is built and rolled out automatically, with no manual steps. The test environment is separate from production.
How we run the servers
- All traffic flows through Cloudflare: web application firewall (OWASP rules), bot detection and rate limiting. The servers themselves are reachable only through that layer: a request that does not arrive via Cloudflare is refused, even by someone who knows the server address.
- The servers are hardened to the CIS Level 1 benchmark, the common industry standard for secure server configuration (last audit September 2026); we share the audit report on request.
- Security updates are installed automatically. Servers are built from code and can be rebuilt within minutes.
- Administrative access to the servers is personal, tied to the role and key-based instead of passwords, behind an identity check. The servers expose no management port to the internet and every administrative session is logged.
How we monitor and recover
- Independent, external uptime monitoring watches the platform 24/7; you can watch it live at status.eclarion.com.
- Performance and error monitoring run continuously, at application and server level; on a deviation the team is alerted immediately.
- Your data is backed up continuously with point-in-time recovery, complemented by daily backups. Every quarter we restore a backup for real. In the latest test (September 2026) the platform was fully rebuilt within a quarter of an hour.
- The concrete commitments on availability, incident communication and recovery times are in our service level agreement, the same for every customer.
How we account for it
- Our data processing agreement applies automatically to every customer and is published on this website, as is the sub-processor list. Per GDPR article: article 28 in the data processing agreement and the sub-processor list, articles 13 and 14 in the privacy policy, article 32 on this page. In case of a data breach we inform you within 48 hours.
- The data centre where our servers run (Hetzner) and all of our sub-processors are ISO 27001 or SOC 2 certified, listed per party on the sub-processors page, with public certificates. Eclarion itself holds no certificate of its own. A certificate confirms that processes are described; this page describes the measures themselves.
- All our legal documents carry a version number and an effective date. Every version remains available as a PDF, so it is always clear which text applied when. The responsible party is Eclarion B.V., established in Arnhem (Dutch Chamber of Commerce 62087282).
Eclarion and NIS2
Since 15 August 2026 the Dutch Cyberbeveiligingswet, the national implementation of the EU NIS2 directive, is in force. Many food companies fall under it as an "important entity" and must then also manage the risks in their supply chain: they need to know which measures suppliers like Eclarion take.
Eclarion itself is not in scope (small enterprise, not a designated sector), but we are set up for your duty of care. The ten measure areas of NIS2 article 21, and where you find our answer:
| Measure area (art. 21(2)) | What we do | Where it is |
|---|---|---|
| a. Risk analysis and security policy | Security policy and the risk assessment behind every infrastructure choice are documented and under version control; this page is the public summary | This page |
| b. Incident handling | Continuous error and performance monitoring with immediate alerting; a documented data breach procedure; notification to you within 48 hours, status updates at least hourly and a root-cause summary afterwards | Data processing agreement, SLA |
| c. Business continuity, backups, crisis management | Continuous backup with point-in-time recovery to a different location (Helsinki) plus daily backups; recovery rehearsed for real every quarter; servers rebuilt from code within minutes; incident communication via status.eclarion.com | SLA |
| d. Supply chain security | Every sub-processor published with function, data, location and certification; a data processing agreement with each party; changes announced at least 30 days in advance; platform and database in the EU, supporting services outside it only under a valid legal framework | Sub-processors |
| e. Secure development and vulnerability handling | Technically enforced security scan on every code change, every release checked for all software libraries (server and browser), included passwords or keys and the operating system, protection against common web attacks, Content Security Policy, and a reporting address for vulnerabilities | This page, "How we build" |
| f. Effectiveness of the measures | Daily automated checks that availability, backups, servers and certificates meet the standard, with an evidence log and alerts on deviation. Automatic security updates, quarterly recovery test, CIS audit on every server, annual review of this policy | This page |
| g. Cyber hygiene and training | Two-factor authentication on all company systems, password manager, least privilege; development and operations sit with the same team, without a hand-over in which knowledge gets lost | This page, "Who can access it" |
| h. Cryptography | Encrypted database disk, encrypted backups, TLS in transit; passwords stored hashed and refused when they appear in a known breach | This page, "Where your data lives" |
| i. Access control and asset management | Permissions per user and per module, strict separation between customer environments, immutable audit trail that also records changes by Eclarion by name, administrative access personal and key-based. Servers and their configuration live entirely in code, so the inventory of the infrastructure is the code itself | This page, "Who can access it" |
| j. Multi-factor authentication and secured communication | 2FA for every user, mandatory per organisation if you choose; SSO via SAML (including Microsoft Entra ID), enforceable by your organisation | This page, "Who can access it" |
Have a supplier assessment or questionnaire to complete? Send it to team@eclarion.com and you get it back quickly, with a substantiated answer to every question.
Found a vulnerability?
Tell us at team@eclarion.com. You will get a substantive response quickly, and we greatly appreciate responsible disclosure.