Skip to content
EMPOBase
en
Start free
Security & privacy

Built on Google Cloud. Plain-language security.

EMPOBase is hosted on Google Cloud. This page covers the controls and policy commitments we operate today, what's on the immediate roadmap, and the vendors who process your data.

What we guarantee, what's in progress, and who processes what — all on this page.

app.empobase.com TLS
Every request, verified
  • In place: Connection encrypted
    TLS in transit · HSTS enforced
  • In place: Identity verified
    Signed token checked server-side, every request
  • In place: Organization scope enforced
    Queries use your authenticated organization context
  • In place: Encrypted at rest
    Google-managed keys on databases and files
  • Operator-blind encryption Roadmap
    Customer-held keys for sensitive records

Illustrative — the checks every authenticated request must clear.

Hosting
Google Cloud
Singapore region. EU / region-pinned residency is on our roadmap.
Encryption
In transit + at rest
TLS in transit. Google-managed encryption at rest.
Isolation
Organization-scoped access
A shared Cloud SQL database with authenticated organization context and application-enforced boundaries.
Standing commitments
  • No data resale
  • Not used to train AI models
  • DPA terms on request
  • Supported exports through our privacy process
  • Every sub-processor named
How requests flow

From your browser to the database, in four hardened layers.

A high-level view of how every authenticated request travels through EMPOBase. Names the layer (Edge / Identity / Application / Storage), not the products underneath.

Edge

  • TLS · HSTS · strict CSP
  • DDoS and bot filtering

Identity

  • Managed Google identity provider
  • Signed tokens, verified server-side

Application

  • Requests scoped to one organization
  • Checked on every API call

Storage

  • Shared Cloud SQL database
  • Private files · authorization checks · short-lived signed URLs

Encryption at rest uses Google-managed keys today. Customer-held, operator-blind encryption for sensitive records is on our roadmap (see below).

What we guarantee

The security floor, in plain terms.

Implementation details are kept private for the same reason banks don't publish their network diagrams. The properties below are the controls and policy commitments we describe publicly today.

Organization-scoped access

  • Records share one Cloud SQL database and carry an organization ID. Authenticated context and organization-qualified queries enforce the boundary.
  • Files are private. EMPOBase checks authorization before issuing a short-lived signed download URL.
  • Each supported API path checks authenticated organization context and required capabilities, not only login state.

Encryption

  • HTTPS/TLS protects browser-to-service traffic and HSTS is enforced. The application connects through Google’s authorized, encrypted Cloud SQL connector.
  • Google-managed encryption keys on data at rest — both databases and file storage
  • Customer-managed encryption keys (BYOK) — on the roadmap for Enterprise, not yet available (see roadmap below)

Identity & sessions

  • Sign-in goes through a managed Google identity provider — your credentials never touch our database
  • Identity tokens are cryptographically signed and verified server-side on every request
  • Session cookies are HttpOnly + Secure + SameSite. JavaScript can't read them; cross-site requests can't replay them
  • Authorised-domain allowlist on the identity provider — phishing pages can't proxy your login

Resilience

  • Cloud SQL keeps fourteen automated backups and seven days of transaction logs for point-in-time recovery.
  • Production credentials are stored in Google Secret Manager with IAM access limited per secret. Secret access is recorded in Cloud Audit Logs.
  • Container-level immutable deploys. No SSH-into-the-server patching; every release is a fresh build replacing the old one
  • Strict Content-Security-Policy + X-Frame-Options + X-Content-Type-Options on every page
Privacy

Your data, your rules. Not training fodder.

We operate the portal. Customers control the data they submit, and we process it to provide and secure the service.

Data ownership
You own the data you submit. We process it to provide and secure the service, and support export requests through our privacy process.
No training, no resale
We do not sell or license customer data, or use customer content to train EMPO or third-party models. Required processors are named below, and applicable DPA terms are available on request.
Right to delete
Per-record deletion is available in supported workflows. Verified account-deletion requests follow our privacy process and applicable retention duties.
Right to export
Supported exports are available in the product and through our privacy process. Format and scope depend on the data and plan.
DPA on file
Applicable Data Processing Agreement terms are available on request for supported processing and transfer arrangements.
Beneficiary data
If you store beneficiary names, photos, GPS coordinates, or identity documents, treat them as sensitive and confirm the access, retention, and redaction controls required for your programme.
Sub-processors

Who else touches your data, and why.

We name the required processors that handle customer data and update this list when those processors change.

Who else touches your data, and why.
Vendor Purpose Data type Location
Google Cloud Hosting, database, file storage, DNS, secrets All customer data Singapore region
Google identity provider Sign-in (Google + email) Email, display name, sign-in timestamps Global
Hostinger Domain registrar Domain ownership records only EU (Lithuania)
Resend Transactional email (receipts, auth, notifications) Email address, message content USA
Stripe Subscription billing (planned — not yet active) Billing contact, email, payment instrument USA · EU available

Sub-processor list is updated as integrations change. Stripe is planned but not yet active.

The honest part

What's on the roadmap, dated.

We're a young product. Pretending to hold certifications we don't would not survive your first intake call. Here is the real state.

Today

Foundational controls

  • Google Cloud-native baseline
  • Application-enforced organization access controls
  • Encryption in transit + at rest
  • DPA template on request
  • Sub-processor list (above)
In progress

2026 H2

  • MFA rollout preparation — enrolment, recovery, and reset verification pending.
  • Customer-facing audit log export
  • GDPR data export + delete endpoints
  • EU data residency
  • Vendor security questionnaire kit
Roadmap

2027

  • SOC 2 Type I
  • Customer-managed encryption keys (BYOK)
  • ISO 27001 audit kickoff
  • Public status page
Talk to us

Send your security questionnaire — we'll answer it.

INGO procurement teams: send your CAIQ, your VSA, your home-grown vendor security checklist. We respond within 5 business days under NDA and walk through any gap.

Responsible disclosure: found a vulnerability? Email security@empobase.com. We acknowledge within 48 hours and credit researchers in the changelog.