Whitepaper
How BookNLink protects customer data — transport, storage, authentication, monitoring and incident response.
Transport
All external traffic is TLS 1.2+; TLS 1.3 is preferred when the client supports it. HSTS is enforced with a two-year max-age and preload.
Authentication
Signed JWTs with a ninety-day rotating key. Scopes are per-property and per-module. Two-factor authentication is enforced for all workspace users.
Encryption at rest
Postgres volumes are encrypted with LUKS. Backups are encrypted with age keys and stored in a second EU data centre.
Journalling
Every request and response is retained for ninety days for audit and incident review. Retention can be extended on request under a data-processing addendum.
Data residency
All customer data resides in Hetzner Cloud data centres in Falkenstein (Germany) with backup replication to Nuremberg (Germany). No transfer outside the EEA occurs.
Incident response
Personal-data breaches are notified to the controller within 72 hours (Art. 33 GDPR). Coordinated disclosure for security researchers: security@booknlink.org, response within 72 hours, remediation within 7 to 90 days depending on severity.
Third parties
Sub-processors: Hetzner Cloud (Germany), Postmark (EU), Stripe Payments Europe Ltd (Ireland). Full list on request.