BookNLink
Security

Whitepaper

How BookNLink protects customer data — transport, storage, authentication, monitoring and incident response.

Transport

All external traffic is TLS 1.2+; TLS 1.3 is preferred when the client supports it. HSTS is enforced with a two-year max-age and preload.

Authentication

Signed JWTs with a ninety-day rotating key. Scopes are per-property and per-module. Two-factor authentication is enforced for all workspace users.

Encryption at rest

Postgres volumes are encrypted with LUKS. Backups are encrypted with age keys and stored in a second EU data centre.

Journalling

Every request and response is retained for ninety days for audit and incident review. Retention can be extended on request under a data-processing addendum.

Data residency

All customer data resides in Hetzner Cloud data centres in Falkenstein (Germany) with backup replication to Nuremberg (Germany). No transfer outside the EEA occurs.

Incident response

Personal-data breaches are notified to the controller within 72 hours (Art. 33 GDPR). Coordinated disclosure for security researchers: security@booknlink.org, response within 72 hours, remediation within 7 to 90 days depending on severity.

Third parties

Sub-processors: Hetzner Cloud (Germany), Postmark (EU), Stripe Payments Europe Ltd (Ireland). Full list on request.