Security Information - Dashboard Application

Last Updated: June 2025

Security Overview

This security information applies specifically to our Dashboard Application. Building Better Teams operates with a security-first approach for our dashboard service. Our infrastructure is self-hosted in the EU, no personal information is stored on our servers, and access is strictly limited to essential personnel. We follow industry best practices for system hardening, regular updates, encryption, and monitoring. All systems are designed with privacy by default and data minimization principles. Companies and users are anonymized at rest to ensure privacy protection.

EU Hosted End-to-End Encryption No Personal Data Storage Regular Security Updates SSH Key Authentication Rate Limiting

1. Infrastructure Security

1.1 Hosting Environment

1.2 System Hardening

2. Application Security

Technology Stack

2.1 Data Protection

2.2 Development Security

3. Access Control

3.1 Administrative Access

3.2 Application Access

4. Monitoring and Incident Response

4.1 System Monitoring

4.2 Incident Response

5. Data Governance

5.1 Data Processing Principles

5.2 Data Location and Transfers

6. Backup and Recovery

7. Compliance and Standards

Security Framework Alignment

Our security practices align with industry standards including:

7.1 Regular Security Reviews

8. Security Contact

Security Vulnerability Disclosure

If you discover a security vulnerability or have security concerns about our dashboard application, please contact us immediately:

Email: brian@buildingbetterteams.de
Response Time: We aim to respond to security reports within 24 hours

Responsible Disclosure Policy

We appreciate responsible disclosure of security vulnerabilities. Please:

9. Architecture Overview

Note: Detailed system architecture diagrams are available upon request for authorized parties conducting security assessments.

Internet/Users HTTPS/TLS 1.3 Hetzner Finland Datacenter Proxmox Hypervisor with Proxy BunkerWeb LXC WAF + Rate Limiting (60 req/min/IP) DDoS Protection Dashboard Application LXC (Debian 12) Nginx Next.js Python PostgreSQL • Authentication cookies only • Anonymized user IDs • No APIs exposed SSH Access: Key-based only, Brian Graham only

10. Security Certifications and Assessments

Security Information Requests

For enterprise customers requiring detailed security documentation or specific security questionnaire responses, please contact:

Email: brian@buildingbetterteams.de