How we protect your data
Reporting data about near misses, accidents and first aid is sensitive. That is why data security is not an add-on for tutelaris but a basic requirement of the platform.
ISO 27001
We follow the requirements of ISO/IEC 27001. A certificate has not been issued so far, and we do not claim one while that is the case.
Aligned with the GDPR
Data processing, processing agreements and deletion concepts are aligned with the EU General Data Protection Regulation.
Hosting in the EU
Your data is stored and processed exclusively in data centres within the European Union.
Encryption
Data is transmitted encrypted via TLS and stored encrypted at rest.
Access control & roles
Within the platform, a fine-grained role and permission model governs who may view or edit which reports, first-aid entries and analyses, from the operator on the line to the head of EHS. Anonymously submitted near-miss reports stay technically separated from real names where the customer enables it.
Tenant separation
Customer data is processed in logically separate spaces, so each company can only access its own reports, first-aid data and analyses.
Availability & backups
Regular encrypted backups and a redundant hosting setup reduce the risk of data loss and keep the platform available in daily operation.
Reporting security issues
If you suspect a security vulnerability, please contact us straight away at andrei.piatrouski@tutelaris.de. We look into every report as a priority.