Security
This page describes how Fiftify Inc. protects the Services and the data our customers entrust to us. It supplements our Privacy Policy and the Data Processing Agreement, including its Appendix 2 (technical and organizational measures).
1. Infrastructure and encryption
The Fiftify application and its database run on DigitalOcean infrastructure in the United States, on managed Kubernetes with a managed PostgreSQL database. Traffic to fiftify.com and app.fiftify.com passes through Cloudflare, which provides DNS, content delivery, web application security, and DDoS protection.
- Encryption in transit. Connections to the Services are encrypted with TLS.
- Encryption at rest. Customer Personal Data is encrypted at rest.
- Logical separation. Each customer's data is logically separated from the data of other customers.
- Monitoring. We monitor our network and applications to detect and respond to operational and security issues.
The providers that host or process Customer Personal Data on our behalf are listed on the Subprocessors page.
2. Access control and roles
Inside a Fiftify account, roles carry View, Manage, and Delete permissions for each area of the product, and access is set per warehouse: a user can manage one location and only view another, or hold a single role across all warehouses. Because warehouse work in Fiftify is confirmed by scans, movement history records who did what, where, and when. Signed-in sessions are protected by authentication cookies, as described in our Cookie Policy.
On our side, administrative access to production systems is limited to personnel who need it for their duties and is protected by multi-factor authentication and role-based access controls. Personnel with access to Customer Personal Data are bound by confidentiality obligations and receive training on security and data protection.
You are responsible for keeping your login credentials confidential and for removing users who no longer need access to your account.
3. Backups and continuity
Customer data is backed up on DigitalOcean infrastructure in the United States, and backups are protected with the same safeguards as production data. We maintain disaster recovery procedures to restore the Services and data after an incident.
After an account is closed, you can access and export your data for 30 days, as described in the Terms of Service. Fiftify deletes Customer Personal Data within 30 days after that export period, and residual copies in backups within 90 days thereafter. Backup copies are not restored or otherwise processed except as required for disaster recovery or legal obligations.
4. Vulnerability disclosure
If you believe you have found a security vulnerability in the Services, please report it to [email protected] with the subject "Security vulnerability". Include a description of the issue, the steps to reproduce it, and the affected URL or feature.
When researching and reporting a vulnerability, please:
- do not access, modify, or delete data that does not belong to you;
- do not degrade the Services, including through denial-of-service testing, spam, or high-volume automated scanning;
- do not use social engineering or physical attacks against our personnel, customers, or providers;
- give us reasonable time to address the issue before disclosing it publicly.
We will confirm receipt of your report, keep you informed while we investigate, and let you know when the issue is resolved.
5. Compliance and questions
Where Fiftify processes Customer Personal Data on behalf of our customers, it does so under the Data Processing Agreement, which incorporates the EU Standard Contractual Clauses, with the UK Addendum and the Swiss adaptations, for international transfers. Subprocessors and their processing locations are listed on the Subprocessors page, and new subprocessors are announced in advance as described there.
If a personal data breach affects Customer Personal Data, we notify the affected customers without undue delay, as set out in the Data Processing Agreement. Please report any suspected breach or misuse to [email protected].
For security questions, or to request information for your own compliance review, contact [email protected].