Technology
Security Policy
Last updated July 22, 2026
Building software for everyone means protecting everyone who uses it. See how we secure our services, and how to report a vulnerability.
Security is foundational to how we build Ordnary. This page gives an overview of our security practices and explains how to report a vulnerability. Read it together with our Privacy Policy and our Data Processing Addendum.
Our security measures
We apply a range of technical and organizational measures to protect our services and your data.
Encryption: data is encrypted in transit (TLS) and, where the relevant service supports it, at rest as well.
Access control: we apply the principle of least privilege, with role-based permissions and strong authentication for internal systems.
Isolation between workspaces: for services with multiple customers on shared infrastructure, we isolate workspaces and customer environments from one another.
Network security: firewalls, network segmentation, DDoS protection, and managed TLS protect our platform.
Logging and monitoring: we log access and key events and monitor for anomalies and abuse.
Secure development practices: we use code review, dependency management, and automated testing in our development process.
Backups and recovery: managed services include backup and recovery capabilities appropriate to the offering; you remain responsible for exporting and verifying critical data.
Vendor management: subprocessors are bound by security and data-protection obligations. See our Subprocessors page.
Shared responsibility
Security is a shared responsibility. We secure the platform and our services; you're responsible for securing your account, credentials, API keys, configurations, workloads, and the data you put into our services. Use strong, unique passwords, enable multi-factor authentication, rotate keys regularly, and grant access only on a need-to-know basis.
Reporting a vulnerability
Think you've found a security vulnerability in an Ordnary service? We want to hear from you. Email security@ordnary.com with:
- a description of the issue and its potential impact;
- steps to reproduce the issue, including affected URLs, endpoints, or components; and
- any proof-of-concept, log files, or screenshots.
Please do
- Give us a reasonable time to investigate and remediate before disclosing it publicly.
- Limit your testing to your own accounts and data.
- Avoid privacy violations, data loss, and disruption of our services.
Please don't
- Access, modify, or delete data that isn't yours.
- Conduct denial-of-service attacks, spam, or social engineering against our staff or users.
- Exploit a vulnerability beyond what's necessary to demonstrate it.
Safe harbor for researchers
We won't pursue, or support, legal action against researchers who in good faith follow this policy and the Acceptable Use Policy, and who avoid privacy violations and disruption of our services. If a third party takes legal action against you for activities carried out in accordance with this policy, we'll make this authorization known to that third party.
Incident notification
If a security incident affects your personal data, we'll inform affected users and, where Ordnary acts as a processor, the relevant controller, in line with our Privacy Policy, our Data Processing Addendum, and applicable law.
Contact
Security reports and questions: security@ordnary.com.
For urgent requests, call +31 85 401 3197.