Security

Last updated: 31 July 2026

Cloudexp OÜ develops Säuts with the principle that security is not an afterthought—it is a fundamental part of the platform's architecture and development process.

We implement technical and organisational measures designed to protect customer data against unauthorised access, disclosure, alteration, loss, or destruction.

While no internet-connected system can guarantee absolute security, we follow industry best practices and continuously improve our security controls as our platform evolves.


Our Security Principles

The development of Säuts is guided by the following principles:

  • Security by Design – security is considered throughout the entire software development lifecycle.
  • Privacy by Design – we collect only the Personal Data necessary to provide the Service.
  • Least Privilege – users and systems receive only the minimum permissions required.
  • Defense in Depth – multiple independent layers of protection are implemented.
  • Secure by Default – secure configurations are used as the default wherever practical.

Data Encryption

Data in Transit

All communication between your device and Säuts is encrypted using HTTPS/TLS.

Encryption helps protect information from interception or tampering while it is transmitted across public networks.


Data at Rest

Databases managed by our infrastructure providers use encryption for stored data (Encryption at Rest).

This provides an additional layer of protection should physical storage media ever become compromised.


Access Control

Access to production systems is strictly restricted.

We implement security controls including:

  • Role-Based Access Control (RBAC);
  • the Principle of Least Privilege;
  • individual user accounts;
  • authentication before access is granted;
  • periodic access reviews.

Production environments are accessible only to authorised personnel whose responsibilities require such access.


Authentication

User accounts are protected using secure authentication mechanisms.

Passwords are never stored in plain text.

Authentication processes rely on modern cryptographic techniques, and passwords are protected using industry-standard hashing algorithms.


Data Isolation

Säuts is a multi-tenant SaaS platform.

Each customer's data is logically isolated from the data of every other customer.

Users can access only the data belonging to organisations for which they have been granted appropriate permissions.

Authorisation rules are enforced on every request before data is returned.


Application Security

We follow secure software development practices throughout the design, implementation, and maintenance of the Service.

Our security measures include, among others:

  • server-side authorisation;
  • input validation;
  • permission checks on every request;
  • regular security updates;
  • dependency management and updates;
  • logging of errors and security-relevant events;
  • continuous monitoring of system health.

When security vulnerabilities are identified, we aim to remediate them within a reasonable timeframe based on their severity and potential impact.


Infrastructure

Säuts is hosted on trusted cloud infrastructure and makes use of managed services to provide a secure, reliable, and scalable platform.

To operate the Service, we may use providers such as:

  • Supabase
  • Cloudflare
  • Vercel
  • BulkGate
  • Twilio
  • Stripe
  • Resend

Each provider processes data only to the extent necessary to deliver the Service.

A current list of our service providers is available on our Subprocessors page.


Backups and Disaster Recovery

We perform regular backups of our production databases to support business continuity and disaster recovery.

Backups are used solely for:

  • restoring systems after technical failures;
  • recovering data following serious incidents;
  • maintaining service continuity.

Backup data is protected using security controls comparable to those applied to production data.


Monitoring and Logging

We continuously monitor the health, availability, and security of the Service.

System logs may be collected and analysed for purposes including:

  • diagnosing technical issues;
  • investigating security incidents;
  • analysing performance problems;
  • improving the reliability and stability of the Service.

Access to logs is restricted to authorised personnel with a legitimate business need.


Security Incident Response

If we become aware of a security incident, we act promptly to:

  • contain the incident;
  • investigate its cause;
  • restore normal service operation;
  • implement measures to reduce the likelihood of similar incidents occurring in the future.

Where a security incident is likely to affect customer or end-user Personal Data, we will notify affected customers without undue delay and fulfil our obligations under the GDPR and other applicable laws.


Subprocessors

We rely on carefully selected third-party service providers to operate the Service.

We seek to work with providers that maintain appropriate technical, organisational, and security standards.

Each Subprocessor processes Personal Data only on our documented instructions and only to the extent necessary to provide the Service.

Additional information is available on our Subprocessors page.


Responsible Vulnerability Disclosure

If you believe you have identified a potential security vulnerability affecting Säuts, we encourage responsible disclosure.

When reporting a vulnerability, we ask that you:

  • provide sufficient technical detail to reproduce the issue;
  • avoid exploiting the vulnerability beyond what is necessary to demonstrate its existence;
  • refrain from accessing, modifying, deleting, or disclosing customer data;
  • allow us a reasonable opportunity to investigate and remediate the issue before making any public disclosure.

We appreciate responsible security research and will treat vulnerability reports confidentially.


Compliance

The development and operation of Säuts are guided by recognised security and privacy principles, including:

  • the General Data Protection Regulation (GDPR);
  • Privacy by Design;
  • Security by Design;
  • the principle of data minimisation;
  • the Principle of Least Privilege.

For additional information, please refer to our:

  • Privacy Policy;
  • Data Processing Agreement (DPA);
  • GDPR & Compliance page.

Security Is an Ongoing Process

Security is a continuous process rather than a one-time effort.

We regularly evaluate our systems, apply software updates, remediate identified vulnerabilities, and continuously improve our security practices to address evolving threats, technologies, and regulatory requirements.


Contact

If you have any questions regarding the security of Säuts or wish to report a potential security issue, please contact us.

Cloudexp OÜ

Registry Code: 16263842

Registered Address:

Juurdeveo tn 18-9
Kesklinn, Tallinn
Harju County 11313
Estonia

Email:

tere@sauts.ee

Website:

https://sauts.ee


This Security page provides a general overview of the security practices implemented by Säuts. It does not form part of any contract and should not be interpreted as a guarantee that any specific security measure will be implemented in every circumstance. Cloudexp OÜ may update this document from time to time to reflect technological, organisational, or legal developments.

Terms of ServicePrivacy PolicyCookie PolicyData Processing Agreement (DPA)GDPR & ComplianceSecurityAboutContactPrivacy Policy

Küsimused: tere@sauts.ee · Avalehele