1. Our Approach
This page describes the technical and organisational measures we apply to protect your data on NetZero E.S., together with their limits. Every item here describes a control that is actually in place; nothing here implies a certificate we do not hold or an audit that has not been performed.
The Platform is developed and operated as an independent student/personal project, not by a registered company (see the Privacy Policy). That does not change how the measures below are applied; it only gives rise to the limits on corporate certification and independent audit set out in Section 9.
2. Infrastructure and Data Location
- Database: Google Cloud Firestore, in the europe-west3 (Frankfurt) region within the European Union.
- Server functions: Google Cloud Functions, in the europe-west1 (Belgium) region.
- Authentication: Firebase Authentication.
- Web server: A server on Microsoft Azure that serves static page files only; no user data is stored on it.
- Content delivery and attack protection: Cloudflare.
Backups: The database is backed up automatically every week and backups are retained for six weeks.
3. Encryption
- In transit: All connections use HTTPS (TLS). The HSTS header prevents browsers from connecting to the site without encryption.
- At rest: Data in the database is stored encrypted on disk by Google Cloud.
- Passwords: Your password is stored by Firebase Authentication as an irreversible hash; the Platform never sees or stores your password in plain text.
- Payment details: Card details are processed only by the payment provider Shopier and never reach the Platform.
- API keys: A key you create is shown once; afterwards only its hash and a shortened preview are stored.
4. Authentication and Access Control
- Email verification: Accounts cannot be used until the email address has been verified.
- Role-based authorisation: Every feature is checked separately in the interface and in the database security rules; the database rules are the actual security boundary, so bypassing an interface restriction does not grant access to data.
- Private by default: Only you can access your calculations. Your data is not opened to another user unless you join a team or a lab, or create an audit link.
- Session and device management: From your profile you can see your open sessions and sign out of all devices in one step.
- Re-authentication for sensitive actions: Actions such as changing your password or deleting your account require you to verify your identity again; critical account actions are notified by email.
- Rate limiting: Public endpoints such as coupon validation, report verification and invitation codes are limited by number of attempts.
5. Application Security
- Content Security Policy (CSP): Inline scripts are not allowed to run; third-party scripts can be loaded only from individually listed sources (version-pinned libraries and reCAPTCHA).
- Integrity checks (SRI): Every externally loaded library is compared by the browser against its expected hash; a modified file is not executed.
- Security headers: HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy are sent with every response.
- Input validation and output escaping: User-supplied data is escaped before it is written to a page; the fields of public forms are validated for type, length and range in the database rules.
- Abuse protection: Automated requests are monitored with Firebase App Check and reCAPTCHA.
- Automated tests: More than 350 automated tests for server functions and database security rules run on every code change; the sign-up, verification and sign-in flow is exercised end to end against the live environment every night.
- Dependency monitoring: The libraries in use are scanned for known vulnerabilities and fixes are applied.
6. Server Security
- Firewall: Only the administration (SSH) and web (HTTP/HTTPS) ports are open on the web server.
- Brute-force protection: Repeated failed login attempts are blocked automatically.
- Updates: Operating system security updates are applied automatically.
- Protection of sensitive files: Configuration files, source repositories and server-side code are not reachable over the web.
7. Monitoring and Incident Management
- Health checks: The website, authentication, database and server functions are checked automatically every 15 minutes; the administrator is alerted immediately when a problem is detected. Current status is public on the Status page.
- Audit trail: Administrator actions and critical account actions are recorded permanently.
- Error monitoring: Technical errors occurring in the browser are recorded for troubleshooting and deleted after 30 days.
- Data breach notification: If a security breach affecting your personal data is detected, the Turkish Personal Data Protection Board is notified within the period required by KVKK (72 hours from becoming aware) and affected users are notified without undue delay.
8. Privacy by Design
- Cookieless measurement: Visitor statistics are kept as daily totals that cannot be linked to an individual, without cookies and without recording IP addresses or user identifiers.
- No advertising or tracking: The Platform uses no third-party advertising, retargeting or analytics tracking tools; your data is not sold or rented.
- On-device processing: With the read-from-invoice feature, the file you select is processed only in your browser and is not uploaded to a server.
- Data ownership: From your profile you can download a copy of all your data and permanently delete your account together with your data.
Which data is processed for which purpose, and for how long, is set out in the Privacy Policy; records kept in your browser are described in the Cookie Policy.
9. Certifications and Limits
In the interest of transparency, we also state plainly what we do not have:
- The Platform does not hold ISO 27001, SOC 2 or any similar information security certification. The measures applied were chosen with ISO 27001 principles in mind; that is not certified conformity.
- The Platform has not yet undergone an independent penetration test.
- Our infrastructure providers (Google Cloud, Microsoft Azure, Cloudflare) hold their own certifications; these cover the provider's service, not the Platform itself.
- Reports produced are drafts and do not replace independent assurance.
10. Sub-processors
| Provider | Function | Data processed |
| Google Firebase / Google Cloud | Authentication, database, server functions | Account and calculation data (within the EU) |
| Google reCAPTCHA | Abuse protection | Browser and device signals |
| Microsoft Azure | Serving static pages | IP address (connection log) |
| Cloudflare | Content delivery, attack protection | IP address, request metadata |
| Resend | Delivery of transactional emails | Email address, message content |
| Shopier | Payments | Payment and billing details |
11. Vulnerability Disclosure
If you have found a security vulnerability on the Platform, please report it to [email protected]. Contact details are also published in machine-readable form in security.txt.
- Include how the vulnerability can be reproduced and its possible impact.
- Allow reasonable time for a fix before disclosing the vulnerability publicly.
- Test only with your own account and your own data; do not access other users' data, do not modify or delete data, and avoid tests that would disrupt the service.
- We will not pursue legal action over research carried out in good faith within these rules.
We aim to respond to reports within five business days. Because the Platform is a student project, there is no bug bounty programme; with your permission we may acknowledge your contribution.