Security at allaboutapps
As a software service provider, we develop and operate systems that our customers trust with their data. Information security is therefore an integral part of our processes - from development and hosting to ongoing support.
This page provides an overview of our key security measures. More detailed documentation, such as our technical and organisational measures, is available to customers and contracting parties upon request.
1. Certifications and Compliance
aaa - all about apps is ISO 9001 certified, with our quality management system covering the entire development and operations lifecycle. Building on this foundation, we operate an Information Security Management System (ISMS) in accordance with ISO/IEC 27001. Certification according to ISO/IEC 27001:2022 is currently in preparation.
2. Data Location and Hosting
We operate customer systems and internal systems exclusively in ISO-certified data centres within the EU - using dedicated servers and cloud instances at Hetzner in Falkenstein, Germany, as well as Google Cloud Platform in Frankfurt.
We do not operate our own server room, and no servers or storage systems containing personal data are hosted at our office. Under the shared responsibility model, physical security of the data centres is provided by the respective certified operators.
Customer systems are logically isolated from one another.
3. Encryption
All data transmission takes place exclusively over encrypted connections using TLS 1.2 or higher, with TLS 1.3 as the standard for new systems, as well as SSH with individual user keys.
Data stored by our cloud providers is encrypted at rest, and all employee devices use full-disk encryption via FileVault or BitLocker.
Passwords and PINs within our applications are stored exclusively as cryptographic hashes using state-of-the-art methods such as Argon2id. Our cryptographic procedures are benchmarked against BSI TR-02102.
Cryptographic keys are centrally managed and rotated immediately in the event of personnel changes or suspected compromise.
4. Secure Development
Our development process follows a documented Secure Development Lifecycle embedded within our ISO 9001 processes.
Every code change undergoes an independent code review and QA approval before release. Development, testing and production environments are strictly separated, and only synthetic or anonymised data is used in development and testing environments.
Dependencies, container images and cloud configurations are automatically and continuously scanned for vulnerabilities. In addition, we conduct risk-based internal security reviews based on the OWASP Top 10. These reviews are performed by individuals who were not involved in developing the respective code.
Our secure engineering principles are aligned with NIST SP 800-160 and OWASP.
5. Infrastructure and Network Security
Our infrastructure is fully provisioned as Infrastructure as Code, ensuring reproducible and consistently hardened environments.
Systems are protected by firewalls based on a deny-by-default approach and segmented at network level using measures such as VPC separation and network policies. Documented hardening baselines are maintained for all technologies in use.
Security-relevant events are centrally logged and regularly reviewed, while all customer systems are continuously monitored for availability and anomalies.
Identified vulnerabilities are remediated within defined timeframes based on severity:
- Critical and high-risk vulnerabilities: within 30 days
- Medium-risk vulnerabilities: within 60 days
- Low-risk vulnerabilities: within 90 days
6. Identity and Access Management
All access is provided through individual user accounts based on the principles of Least Privilege and Need-to-know, with permissions managed through role-based access controls.
Two-factor authentication is mandatory for all services that support it, and privileged access to production systems requires MFA. Access rights are reviewed quarterly. When employees leave the company, all access permissions are revoked within three business days. Direct database access is limited to troubleshooting purposes, is only permitted through individual accounts from within our internal network, and is fully logged.
7. Personnel Security
New employees undergo lawful and proportionate screening and are contractually bound to confidentiality.
All employees complete basic information security training during their first month and participate in annual refresher training, including phishing simulations. Acknowledgement of our security policies is documented annually.
8. Suppliers and Subprocessors
Service providers and subprocessors are assessed on a risk-based basis before engagement, including reviews of relevant ISO 27001 certifications and SOC 2 reports. They are maintained in a supplier register and reviewed at least annually. Data processing agreements in accordance with Article 28 GDPR are in place with all subprocessors. Suppliers classified as medium or high risk are subject to contractual notification obligations in the event of security incidents.
9. Security Incident Management
We operate a documented incident response process with defined severity levels, responsibilities and an operational runbook. Security incidents can be reported at any time via security@allaboutapps.at. Affected customers are informed within 24 hours of security incidents relating to their systems. Personal data breaches subject to regulatory notification requirements are reported to the competent supervisory authority within 72 hours, in accordance with Article 33 GDPR. Every incident is followed by a root cause analysis, and the findings are incorporated into our continuous improvement processes.
10. Business Continuity and Disaster Recovery
All customer data is backed up daily using encrypted, rotating backup generations. Our Recovery Point Objective (RPO) is a maximum of 24 hours, while recovery times are defined by the respective contractual SLAs.
Because our entire infrastructure is provisioned as code, systems can also be reproducibly restored following a complete infrastructure failure.
Recovery procedures and disaster recovery plans are tested at least annually, including restore tests and emergency exercises.
Our organisation is fully capable of remote operation, meaning that an outage affecting our office location does not impact the operation of customer systems.
11. Data Retention and Deletion
We process customer data exclusively within the scope agreed contractually.
At the end of a contract, we provide the option to export the relevant data before it is deleted. Backups expire automatically according to the applicable rotation schedule, no later than after 12 months. Targeted deletion can also be performed upon request.
The systems we develop and operate support the exercise of data subject rights under the GDPR, including access, rectification, deletion and data portability.
12. Customer Responsibilities
Security is a shared responsibility.
We ask our customers to use strong authentication mechanisms within the systems we provide, keep users and roles within their area of responsibility up to date, treat access credentials confidentially, and provide us with current contact details for security-related notifications.
13. Reporting Vulnerabilities
We welcome reports from security researchers and users.
Suspected vulnerabilities in our systems can be reported via security@allaboutapps.at.
We treat reports confidentially, acknowledge receipt promptly, and keep the reporting party informed about the remediation process.
14. Information Security Policy
Information security is a fundamental part of how aaa - all about apps GmbH ("the Company") works with customers, partners and employees. The Company operates an Information Security Management System (ISMS) in accordance with ISO/IEC 27001 and is committed to the following principles:
Protection of information and IT assets. The Company protects its information and IT assets - including computers, mobile devices, network equipment, software and sensitive data - against internal, external, intentional and accidental threats, while minimising the risks associated with theft, loss, misuse or damage.
Confidentiality. Information is protected against disclosure to unauthorised parties. Access to information is granted according to the principles of Need-to-know and Least Privilege and is strictly controlled and regularly reviewed.
Integrity. Information is protected against unauthorised modification.
Availability. Authorised parties are able to access the information required for business processes when needed. Business continuity plans are developed, maintained and tested.
Legal and regulatory compliance. The Company complies with all applicable legal, regulatory and contractual requirements - in particular the GDPR and the Austrian Data Protection Act - and aims to exceed these requirements wherever reasonably possible.
Continuous improvement. The ISMS is continuously improved through corrective actions, internal audits and management reviews.
Security awareness. All employees participate in regular information security training. Responsibility for security is an integral part of our corporate culture.
Responsibility and reporting. A designated Head of Information Security manages and oversees the Company's information security programme. Actual or suspected security incidents can be reported at any time via security@allaboutapps.at. Individuals who report a security concern in good faith will not suffer any disadvantage as a result.
Contact
For questions regarding information security, requests for security documentation such as our technical and organisational measures, or to report a security incident or vulnerability, please contact: