Depozza handles bookings, payments and identity documents between strangers. That only works if the platform is trustworthy, so security is built into the product rather than bolted on. This page describes the controls we actually operate — nothing more.
Every table enforces row-level security, and sensitive columns such as payment identifiers and KYC data are revoked at column level so they can never be read from the public interface.
The application and database run on managed European infrastructure. Backups are encrypted and retained by our infrastructure provider.
Card details never reach Depozza's servers. Payments and payouts run through Stripe, a PCI-DSS Level 1 certified provider.
Account security
Accounts are protected by our managed authentication provider; we never see or store your password.
- Passwords are hashed by the authentication provider and checked against known breach lists.
- Two-factor authentication is available in Settings and recommended for hosts receiving payouts.
- Sessions are token-based and expire automatically; signing out clears local session data.
Data protection
We collect the minimum needed to run a booking, and delete what we no longer need.
- All traffic is encrypted in transit with HTTPS/TLS; data at rest is encrypted by the database provider.
- Identity documents are stored in private buckets and only readable by their owner and, when required, our verification partner.
- You can request access, correction, export or deletion of your data at any time — see the Privacy Policy.
Access control and logging
Administrative capabilities are enforced by the database, not the interface.
- Admin status is verified server-side on every privileged operation; it cannot be granted from the browser.
- Sensitive administrative actions (disputes, payouts, account changes) are written to an append-only audit log.
- Access to production data is limited to the people who need it, using separate database roles.
Third parties
We rely on a small number of specialised providers and share only the data each one needs.
- Payments and payouts: Stripe. Identity verification: our KYC partner. Transactional email: our email provider.
- We do not sell personal data and we do not run advertising or tracking cookies.
Incidents and continuity
We prepare for failure as well as for attack.
- If a breach affects your personal data, we notify you and the competent supervisory authority within 72 hours, as required by the GDPR.
- Encrypted database backups are taken continuously by our infrastructure provider and can be restored point-in-time.
Certification status
Depozza is not currently certified under SOC 2, ISO/IEC 27001 or any equivalent scheme, and we do not display badges we have not earned.
- Our internal controls are designed with reference to the ISO/IEC 27001 and SOC 2 control families — access control, change management, logging, incident response — but no external auditor has assessed them.
- HIPAA does not apply to Depozza: we do not collect, process or store health information.
- If we complete an independent audit, we will publish its scope and date on this page.
Report a vulnerability
If you believe you have found a security issue, email us with the steps to reproduce it. Please do not access, modify or delete other people's data while testing. We acknowledge reports within 5 business days and will keep you updated until the issue is closed.
security@depozza.euThis page describes Depozza's own security practices and commitments. It is not a certification, an audit report or a legal guarantee.