UTOVER
Company Profile

Security

Overview of the UTOVER approach to security.

UTOVER combines web application development with controlled access, separate data domains, and operations that account for recovery. This overview describes selected safeguards in our own working environment and web platform.

Identity and access

The use of security keys is mandatory throughout the company. Our administration platform uses WebAuthn with required user verification and authentication bound to the service.

Permissions distinguish between reading, editing, and administrative tasks. Access is checked on the server against the assigned role and user group. Sign-in activity and security-relevant administrative actions are logged.

Data separation and protection

The public website and internal administration use separate data domains and access permissions. Public content is made available through a dedicated publication process; the website cannot directly access internal administration tables. Data is transmitted over HTTPS. Selected sensitive data is also encrypted at the application level before storage. This encryption also verifies the integrity of that data.

Operations and recovery

Backups are performed daily. Recovery is tested monthly in practice. These tests check that backed-up data can actually be restored.

Working with enterprise customers

Security requirements depend on the engagement, the data being processed, and the systems involved. The following matters are particularly relevant when defining technical and contractual requirements:

  • Data processing agreement (DPA): Where personal data is processed on behalf of a controller, an agreement under Article 28 GDPR is required before processing begins. The parties' actual tasks and responsibilities determine their roles.
  • Technical and organizational measures (TOMs): The specific protection requirements and the measures intended to address them need to be documented for the engagement. This public overview does not replace a complete description of those measures.
  • Non-disclosure agreement (NDA): The purpose, authorized recipients, and handling of confidential project information can be defined in a separate agreement. An NDA does not replace a DPA where one is required.

For questions about these documents and requirements for your vendor assessment, please contact hello@utover.com. The scope of services, responsibilities, and any service commitments are set out in the applicable agreements.

Reporting security concerns

Potential security vulnerabilities can be reported to security@utover.com. Please identify the affected system and describe your observation without including credentials or other people's personal data.

Information about the processing of personal data on this website is available in our Privacy Policy.