Skip to content

Legal

Security

Last updated: 2026-04-18

How we protect your data

Security is a day-one concern at Klimaro. The same practices that protect a customer's HVAC installations protect their business data.

Infrastructure

  • All traffic is served over TLS 1.2+ with HSTS enforced.
  • Cloudflare in front for WAF, DDoS protection, and rate limiting.
  • Application runs on hardened Linux + Nginx + PHP-FPM on EU-hosted VPS.
  • Managed MariaDB with automated daily backups, 30-day retention, point-in-time recovery on Enterprise.

Authentication

  • Password hashing with bcrypt (12 rounds).
  • Optional Google OAuth for SSO.
  • Session cookies are HTTP-only, Secure, and SameSite=Lax.
  • Enterprise: SAML / OIDC SSO, forced 2FA, IP allowlists.

Application

  • Strict CSP, X-Frame-Options, and modern security headers.
  • Role-based access control with audit logging.
  • Input validation at the framework level; parameterised queries end-to-end.
  • Quarterly dependency updates, monthly security patches.

Responsible disclosure

Found a vulnerability? Email [email protected]. We'll acknowledge within 72 hours, fix promptly, and credit you if you wish.