We specialise in tuning Java EE servers: Oracle WebLogic and IBM WebSphere.

Log in WebMail Jobs

1. Technical safeguards

Encryption and transport

Network architecture

System hardening

2. Access management

Authentication & authorization

Audit logs

3. Compliance and standards

AreaStandardStatus
Personal data protectionGDPR (EU 2016/679)Compliant — see Privacy policy
Information security managementISO/IEC 27001:2022Aligned (processes conform, no formal 3rd-party certification)
Web application securityOWASP Top 10 (2021)Full mitigation — code review + WAF + dedicated tests
Payment securityPCI-DSSHosting in SAQ-A mode (e-commerce customers — redirect to a certified processor)
Data jurisdictionPoland / EUFull — data centre in Poland, no transfers outside the EEA

Enterprise customers (T-Mobile, PZU, BASF, Samsung) are subject to additional contractual requirements. Individual SLAs, DPAs and security questionnaires are prepared on request.

4. Operational processes

24/7 monitoring

Backup and recovery

5. Security breaches

Procedure compliant with GDPR Art. 33–34:

PhaseTimeActions
Detection< 15 minSOC alert, resource isolation, preserve evidence
Triage< 1 hSeverity classification (P1-P4), appoint incident commander
Containment< 4 hLimit impact, stop the attack vector
Notification — UODO< 72 hReport the breach to the President of the UODO (GDPR Art. 33)
Notification — customer< 24 hNotify the customer affected by the breach
Notification — individualsWithout undue delayIf high risk (GDPR Art. 34)
ResolutionRTO targetRestore the service, verify
Post-mortem+ 7 daysRoot cause analysis, report, action items

6. Audits and tests

7. Responsible disclosure

If you discover a vulnerability in our infrastructure or services, do not disclose it publicly before reporting it to us. We work constructively with security researchers.

Contact

Scope

Rules

8. Contact