Security Policy

How TechVerdi SA protects the Kappino platform and the data it holds — our encryption, backups, recovery, access controls, logging, and infrastructure security, in line with Swiss data protection law.

Effective date: 29 June 2026
Last updated: 29 June 2026
Version: 1.0

At a glance

  • Core platform and data are hosted in Switzerland with Infomaniak.
  • Data is encrypted in transit using TLS/HTTPS and HSTS; sensitive credentials and tokens are encrypted at rest using AES-256-GCM.
  • Passwords are hashed with bcrypt; access is controlled through role-based access and tenant isolation.
  • Daily backups, a disaster-recovery plan, and audit logging are in place.
  • We run penetration tests, vulnerability assessments, internal audits, and maintain an incident-response procedure.
  • MFA is on our roadmap and is not yet enforced for login.
1

Overview & commitment

This Security Policy describes the technical and organisational measures that TechVerdi SA — Av. Charles-Ferdinand Ramuz 60, 1009 Pully, Switzerland — applies to protect the Kappino platform, the “Service”, and the data it processes.

It supports our obligations under Art. 8 of the Swiss Federal Act on Data Protection (FADP) and the data-security requirements of the Data Protection Ordinance (DPO), which require measures appropriate to the risk to ensure the confidentiality, integrity, availability, and traceability of personal data.

Security is risk-based: we apply measures appropriate to the nature, scope, and sensitivity of the data and the threats we face, and we review and improve them over time. No system can be made perfectly secure, and this Policy describes our measures rather than guaranteeing a specific outcome.

2

Security governance

We maintain formal, enforced security policies and procedures covering access control, data protection, authentication, and secure development.

Security responsibilities are defined within the organisation, and security is built into our development lifecycle through secure development practices. We conduct periodic internal security audits to review system configurations, access controls, and compliance with our security standards.

We also maintain separate documentation for backups, disaster recovery, and incident response.

3

Encryption

3.1 Encryption in transit

All traffic between users and the Service is encrypted using HTTPS/TLS. We enforce HTTP Strict Transport Security (HSTS) to require secure connections, and apply a Content Security Policy (CSP) to reduce client-side risks.

3.2 Encryption at rest

Sensitive credentials and tokens are encrypted at rest using AES-256-GCM. The application database resides on Swiss-hosted infrastructure protected by the access controls and network measures described in this Policy.

The database itself is not separately encrypted at rest. We continue to review our at-rest encryption posture as part of our ongoing security improvements.

4

Password security

User passwords are stored only as salted hashes using bcrypt — never in plain text, and never recoverable by us.

Authentication uses token-based JWT sessions with session management. We recommend that all users choose strong, unique passwords and do not reuse credentials across services.

You are responsible for keeping your credentials confidential and for the activity of your authorised users, as described in the Terms & Conditions and Section 14 of this Policy.

5

Multi-factor authentication

Current status. Multi-factor authentication is not yet enforced for login to the Service. It is a planned enhancement on our security roadmap.

Until MFA is available, we mitigate account-access risk through bcrypt password hashing, token-based sessions, role-based access control, tenant isolation, rate limiting, and audit logging of authentication events.

In the meantime, we strongly recommend that account administrators use strong, unique passwords and limit the number of privileged users. We will update this Policy when MFA is introduced.

6

Access management

Role-based access control (RBAC) restricts what each user can see and do, on a need-to-know, least-privilege basis.

Tenant isolation logically separates each Business Customer’s data within our multi-tenant environment, so one customer cannot access another customer’s data.

Access to production data at the application level is limited to authorised administrators and scoped API keys, each granted only the access required for their role.

Access rights are reviewed as part of our periodic internal audits and revoked when no longer needed.

7

Infrastructure security

Swiss hosting. The Service runs on virtual private server infrastructure provided by Infomaniak SA, with servers and infrastructure physically located in Switzerland.

Network protection. We apply HTTPS/TLS, HSTS, CSP, and rate limiting, together with firewalling and network controls to protect against abuse and unauthorised access.

Environment separation. We maintain separate development, testing, staging, and production environments so that changes are tested before reaching production data.

Multi-tenancy. The platform is multi-tenant with tenant-based isolation.

Hardening & updates. Systems are configured securely and maintained, with security reviewed during internal audits.

8

Audit logs & monitoring

We maintain audit logs that track key events, including authentication, backup operations, API-key actions, and selected system activities.

These logs support traceability, help us detect and investigate suspicious activity, and assist with incident response. Logs are retained for as long as needed for security and fraud-prevention purposes and are protected against unauthorised access and tampering.

9

Backups

The platform database is backed up as snapshots on a daily, every 24 hours, schedule. Backups are complemented by the backup services of our hosting provider.

Backups are retained on a rolling cycle of up to 90 days and then overwritten or securely deleted. This also governs how residual copies of deleted data are removed, as described in the Privacy Policy and DPA.

We protect backups with the same care as production data.

10

Disaster recovery & business continuity

We maintain a disaster-recovery plan designed to restore the Service and data in the event of a significant failure or incident.

The plan is supported by our daily backups and by the resilience and backup services of our Swiss hosting provider. It covers data restoration from backups and the steps needed to bring the Service back into operation, and is reviewed and updated as our infrastructure evolves.

11

Vulnerability management & testing

We perform vulnerability assessments periodically and conduct penetration testing of critical system components before major releases and after significant infrastructure changes.

Findings are triaged by risk and remediated on a prioritised basis. Secure development practices and code review help reduce vulnerabilities before release.

12

Incident response & breach notification

We maintain an incident-response procedure to detect, respond to, contain, and mitigate security incidents and personal data breaches, including escalation workflows and post-incident reviews to learn and improve.

If a personal data breach occurs that is likely to result in a high risk to the personality or fundamental rights of data subjects, we will notify the Federal Data Protection and Information Commissioner (FDPIC) and, where required, affected individuals, without undue delay and in accordance with the FADP and, where applicable, the GDPR.

Where we act as a processor for a Business Customer, we will notify that customer without undue delay so they can meet their own obligations, as described in the DPA.

13

Third-party & AI data security

Some features rely on third-party providers and sub-processors, as described in the Privacy Policy and DPA.

In particular, documents submitted to the OCR / AI Scanner are processed by Google Cloud Vision and OpenAI, which may involve processing outside Switzerland under appropriate transfer safeguards.

We select providers with appropriate security practices, impose data-protection obligations on processors, and transmit data to them over secure connections. We do not directly store user data with third parties except as described in our documentation, for example documents temporarily processed for OCR.

14

Shared responsibility

Security is a shared responsibility. We secure the platform and infrastructure; you are responsible for security within your own use of the Service, including:

  • protecting account credentials and managing your authorised users and their access levels;
  • promptly removing access for users who no longer need it;
  • configuring features, including messaging, AI, and location features, lawfully and appropriately; and
  • notifying us promptly of any suspected compromise of your account.
15

Reporting a vulnerability & contact

If you discover a security vulnerability or suspect a security incident, please report it to us promptly at office@techverdi.ch with enough detail to investigate.

We ask researchers to act in good faith, avoid accessing or altering data that is not their own, and give us a reasonable opportunity to respond before any public disclosure.

16

Changes & governing law

We may update this Security Policy to reflect changes in our practices, technology, or legal requirements. Material changes will be notified and the “Last updated” date revised.

This Policy is governed by Swiss law, and the competent courts of the Canton of Vaud, Switzerland — place of jurisdiction: Pully / Lausanne — have exclusive jurisdiction, subject to any mandatory place of jurisdiction.

TechVerdi SA — Security

Av. Charles-Ferdinand Ramuz 60, 1009 Pully, Switzerland
Email: office@techverdi.ch
VAT / UID: CHE-110-027.685