
Security controls have a status, a limit and a test.
The product is a prototype. Code checks and passing tests do not establish legal compliance, certification or safety for live personal data.
| Area | Current evidence | Open work |
|---|---|---|
| Company and role access | Implemented and covered by access tests | Independent penetration test remains open |
| Session protection | Secure cookie and account controls in code | Pilot identity and recovery exercise remains open |
| Database backup | Ordered export and local restore drill | Production recovery time and data-loss targets not measured |
| File storage and malware scanning | Uploads disabled while R2 is unconfigured | Do not enable uploads without storage and scanning policy |
| Invoicing and finance | Operational finance and XML pre-draft | No official e-invoice submission or certified double-entry ledger |
| Privacy requests | No destructive name-based anonymisation exposed | Verified identity, record scope, retention and review needed |
Turkey and Europe
KVKK and GDPR applicability depends on the actual organisation, data, purpose, location and contracts. Before using real customer data, identify controller and processor roles, lawful basis, retention, rights handling, subcontractors, transfer routes, incident response and independent review. No ISO, HIPAA or GDPR certification is claimed.
← Back to platform