Home
Pricing
Blog
Sign up - it’s free
Sign up - it’s free

Data Security

Keeping your data safe 🔐

Here’s a description of some of our technical and organisation security measures that we use to secure Fider and protect your personal data. Please bear in mind it's not safe to publicise all our securuty measures and the nature of web security is ever changing, and so must the measures we adopt.

Data Location 🌏

Fider is hosted with AWS (Amazon Web Services). This places your data in their data centres in America (New York).

Encryption

When data is moving between you (your web browser) and Fider, everything is encrypted and sent securely using HTTPS .

Data moving through Fider services is encrypted in transit using an appropriate encryption technology.

Your data is encrypted at rest using Transparent Data Encryption .

Internal access controls

Our team doesn't have a reason to access or process customer data on a day to day basis. It's only if there's a problem or to help resolve a customer support question that we might need to access personal data.

All our team members are aware of their responsibilities in protecting your data and have undertaken GDPR training in respect of their roles.

We use role based access controls for staff and use two-factor auth on both internal apps and external services.

Resiliance & availability

Fider is hosted in AWS data centres in the USA. AWS is one of the industry norms for software hosting and comes with extensive application and infrastructure monitoring.

We also take advantage of their physical, environmental and infrastructure controls.

AWS is independently certified to ISO 27001, 27017, and 27018 and these standards cover and accredit their physical security controls.

Identification & authorisation

Fider is a password-less application so we don’t have to worry about complex password rules and storing them - access is secured by email address and a one time code sent to the user when they try to login.

We also offer Single Sign-On (SSO) to access Fider within admin settings.

Uptime & monitoring

We monitor our infrastructure to make sure it’s up and running 24/7, if anything happens we are ntoified straight away and can get on with fixing it.

Data transfers

We use sub-processors to help deliver Fider, and sometimes this means transferring your data to a 3rd party.

In all cases we make sure that an adequate level of data protection exists by assessing their security and having in place appropriate, GDPR compliant, data processing contracts.

Minimisation and retentiaion

An important factor in data protection is to make sure we don’t collect and store any more data than needed to provide you with Fider. Every piece of data we collect and store must be backed up with a justifiable reason.

If personal data is no longer required it is deleted, either by you - the client, or by automated script when data hits its maximum retention period.

Data quality

All of the data processed is provided by you (the data controller) or your end users (the data subjects), so the quality of data that we hold is governed by you and your users.

All our payments are processed through Stripe https://stripe.com/gb They are a PCI Service Provider Level 1 organisation. Using Stripe means we don't need to store your payment card details, they are sent encrypted directly to Stripe, we don't store them anywhere.

Deletion & portability

Fider has built-in backup and reporting tools that allow you to export your data, and at your request we can permanently erase all data.

Payment card data

Our payments are processed through Stripe https://stripe.com/gb. Stripe are a PCI Service Provider Level 1 organisation. We use them because it means we don't need to store your payment card details on our stsrems, they are sent encrypted directly to Stripe, we don't store them anywhere.

You can read more about security at Stripe here: https://stripe.com/docs/security/stripe

Reporting security problems

We're happy to work with security researchers, they're an important part of keeping the internet a safe place to work. We have a defined process for reporting security issues.

Questions 🙋‍

If you have any questions about this security policy then please reach out to our team and we'll do our best to help.

Your no-fluff product feedback board.
Home
About
Support
Blog
Pricing
Fider Docs
Bluesky
GitHub
Terms & Policies
Privacy Policy
Self Hosting
Fider is a project by Northern App Labs Ltd.
Company No: 15777089
©<current-year> Fider.io