Security
Security, stated as facts
Each point below describes how Regsta works today. What is not in place yet has its own section, so you can judge for yourself.
Jump to what is not true yetYour data stays with your company
- Kept apart in the database
- Each company's data is separated by row-level security, enabled and forced on the application tables. Users in another company cannot read your data. The database refuses the query, even if the application has a bug.
- Tested by trying to break it
- An automated test suite tries to read, write and impersonate across companies as the application's own restricted database role, and expects every attempt to be refused. Its latest recorded run predates our move to Hetzner in August 2026. Running it again on the new servers is open work.
- Roles checked on the server
- Admin, Planner, Payroll, Auditor and employee roles decide what each person can do. The role is checked on the server before data changes, not only by hiding buttons.
- Our own access is written down
- Regsta's own operators can reach company data for maintenance. On each day an operator opens a company's data, a row is written to that company's audit trail.
An audit trail the database keeps
- Changes cannot be rewritten
- Clock events, corrections, approvals and exports are written to an audit trail. The database does not allow those rows to be changed or deleted during the retention period.
- Corrections keep the original
- A correction needs a reason. The original time entry is kept, locked, next to the new version.
- What it is not
- The audit trail has no hash chain and no signatures. Its protection comes from database rules and access control. SHA-256 is used for export files: the inspection folder's file list and the payroll file checksum.
Where your data lives
- Database and sign-in in Germany
- The primary database and sign-in run on servers from Hetzner Online GmbH in Falkenstein, Germany, since August 2026. The location is verified from the network (reverse DNS and IP location). Confirmation against the hosting contract is still open.
- Application in Frankfurt
- The application runs on Vercel in the Frankfurt region, Germany.
- Other providers, listed
- E-mail delivery, rate limiting and push notifications use other providers. Each one, with its region or what is still unconfirmed, is on the subprocessors page.
Connections, sign-in and keys
- Encrypted connections
- Traffic is encrypted with TLS, and HSTS tells browsers to use HTTPS only.
- Browser protections
- Pages carry a Content Security Policy, and other sites cannot show Regsta inside a frame.
- Sign-in cookies
- The sign-in cookie is HttpOnly, Secure and SameSite=Lax. It lasts 30 days and is renewed while you are active.
- Rate limits on sign-in
- Sign-in, sign-in links and sign-up are rate-limited per IP address and per account.
- Sign out everywhere
- One action ends all of an account's sessions, for example when someone leaves the company.
- API keys
- API keys are stored only as a SHA-256 hash.
- Webhook secrets
- Webhook signing secrets are encrypted with AES-256-GCM, and each delivery is signed with HMAC-SHA256.
Backups
- Copies off the server
- The database is backed up continuously, with a separate nightly copy, to storage apart from the production server.
- Restore not yet tested for Regsta
- The restore process has been tested on the shared backup system, but a test restore of Regsta's own database has not been done yet.
No tracking
- Strictly necessary cookies only
- The app sets only the cookies it needs to work: the sign-in cookie, and one that remembers which company you are working in.
- No ads, no profiling
- No advertising or profiling cookies, no Google Analytics and no ad pixels. The marketing pages use Vercel's cookieless visitor statistics. The app uses none.
- No location tracking
- No GPS, no geofencing and no photos when someone clocks in. Regsta records times, not places.
- We do not sell your data
- No data is sold or used for advertising. Only the providers on the subprocessors list process it.
What is not true yet
The gaps, stated plainly, so you do not have to find them yourself.
- No independent penetration test or third-party security audit has been done.
- No ISO 27001 certification, and none in progress.
- No SOC 2 report, and none in progress.
- No multi-factor sign-in (MFA). Accounts are protected by a password or a sign-in link.
- No legal document has been reviewed by a lawyer yet. The terms, privacy policy, DPA and cookie policy are drafts awaiting legal review.
- No field-level encryption of personal data such as names. Protection relies on encrypted connections, access control and row-level security.
- No tested restore of Regsta's own database yet.
- The cross-company test suite has not yet been run again on the new servers.
Read the documents
The details behind this page.
Found a security problem?
Write to the address below. Tell us what you found and how to reproduce it.
security@regsta.comSee it for yourself
Create a free account and look at the audit trail, roles and exports with your own test data.