Turvallisuusstandardit

Miten suojaamme alustan, tietosi ja yhteisön: tietoturvatoimet, moderointi ja parhaat käytännöt koko Votinova-palvelussa.

Päivitetty viimeksi: 18 June 2026|13 osiota
Kaikki asiakirjat ovat saatavilla kuudella kielellä: espanja, englanti, italia, viro, ranska ja saksa. Ristiriitatilanteessa englanninkielinen versio on ratkaiseva.
01

Atbion OÜ's security commitment

1.1. Atbion OÜ — a private limited company (Osaühing) incorporated under Estonian law, with registry code 16890390, VAT number EE102728154 and registered office at Ahtri tn 12, Kesklinna linnaosa, Tallinn 15551, Harju maakond, Estonia ("Atbion", "we") — operates Votinova, a software service for interactive presentations and real-time audience voting.

1.2. Information security is a guiding principle in the design, development and operation of the Platform. These Security Standards describe the technical and organisational measures that Atbion OÜ applies to protect the confidentiality, integrity and availability of the data of Customers, of the members of their Organisation and of the Participants who join the sessions.

1.3. These measures support Atbion OÜ's data protection obligations under Regulation (EU) 2016/679 (GDPR), in particular its Article 32 (security of processing), and are complemented by the Privacy Policy and the Data Processing Agreement.

1.4. These Standards relate to information and platform security. The measures evolve with the state of the art; Atbion OÜ reviews and updates them periodically.

02

Encryption

2.1. Encryption in transit. All communications between users' devices and the Platform, as well as the internal communications between its components, are protected by means of TLS (Transport Layer Security) with configurations in line with industry best practices.

2.2. Encryption at rest. The data stored in the main database and in the backups is encrypted at rest. Atbion OÜ does not store passwords in plain text (see clause 3).

2.3. Hosting in the European Union. The Platform's data is stored and processed on infrastructure located in the European Union, in accordance with the details in clause 4 and with the transfer safeguards described in the Privacy Policy.

03

Authentication and credential management

3.1. Password storage. Users' passwords are never stored in plain text. They are protected by means of an industry-standard memory-hard key derivation function (Argon2), designed to resist brute-force attacks and specialised hardware. For security reasons, Atbion OÜ does not disclose the exact configuration parameters.

3.2. Session tokens. Access to the Platform is managed by means of asymmetrically signed tokens (JWT with RS256). The access token has a short lifetime (30 minutes) and the refresh token a limited lifetime (7 days) with rotation on each use and a revocation list that allows compromised or closed sessions to be invalidated.

3.3. Two-step verification (2FA). The Platform offers two-step verification by means of time-based one-time passwords (TOTP), compatible with the usual authentication apps. Its activation is strongly recommended.

3.4. Third-party sign-in. Users may sign in by means of trusted identity providers ("Sign in with Google" and "Sign in with Apple"), delegating credential authentication to those providers and validating the identity token received.

3.5. Participants. By default, the audience joins the sessions anonymously and without an account, by means of an ephemeral identifier and a short-lived participant token bound to the session. Participants are not required to create credentials unless the Customer activates the authenticated mode.

04

Infrastructure

4.1. Compute and hosting. The Platform runs on Amazon Web Services (AWS) infrastructure, by means of container orchestration (Amazon EKS), in a European Union region. AWS acts as a processor and maintains security certifications recognised in the industry.

4.2. Database. The main database is managed on MongoDB Atlas, with the cluster located in a European Union region.

4.3. Real-time data. Redis is used for real-time voting counters, results broadcasting and coordination between instances, keeping latency low without writing every vote to the database on the critical path.

4.4. Payments. Payments are processed through Stripe. Atbion OÜ does not store or process full payment card data on its own infrastructure; such data is handled directly by Stripe, which complies with the PCI DSS standard (Payment Card Industry Data Security Standard). The details of the billing model are set out in the Payments and Refunds Policy.

05

Access control

5.1. Least privilege. Access to systems and data is granted in accordance with the principle of least privilege: each person and each component has only the permissions strictly necessary for its function.

5.2. Role-based access control (RBAC). Within each Organisation, permissions are assigned by roles (owner, administrator and presenter), so that each user only accesses the functionalities corresponding to their role.

5.3. Multi-tenant isolation. The architecture guarantees the logical isolation of data per Organisation: each query is scoped to the corresponding Organisation, and the identifiers provided by the client are verified against the user's membership before access is granted. One Organisation cannot access another's data.

06

Backups and business continuity

6.1. Backups. Atbion OÜ performs periodic backups of the Platform's data. The backups are encrypted and retained in accordance with the applicable retention policies.

6.2. Resilience. The infrastructure relies on managed services with redundancy that reduce the impact of isolated failures and enable service recovery.

6.3. Continuity. Atbion OÜ maintains recovery procedures aimed at restoring the service and the data within a reasonable timeframe in the event of an incident, and reviews them periodically.

07

Incident management and breach notification

7.1. Incident response. Atbion OÜ maintains procedures to detect, contain, investigate and remediate security incidents, as well as to record the lessons learned.

7.2. Breach notification. In the event of a personal data security breach, Atbion OÜ will act in accordance with the Articles 33 and 34 of the GDPR: notification to the competent supervisory authority (Andmekaitse Inspektsioon) without undue delay and, where applicable, within a maximum period of 72 hours, and communication to the affected individuals where the breach may entail a high risk to their rights and freedoms.

7.3. Processor role. Where Atbion OÜ acts as processor in respect of Participants' data, it will assist the Customer (controller) in complying with its notification obligations, in accordance with the Data Processing Agreement.

08

Content moderation and security

8.1. Automated moderation. The Platform applies automated moderation of the content that Participants contribute or that is displayed to the audience, by means of AWS Rekognition (analysis of images) and AWS Comprehend (analysis of text), in order to detect potentially unlawful or inappropriate content before it is broadcast.

8.2. Human review. The automated filters are complemented by human review: the presenter may moderate the open questions and answers of their session, and Atbion OÜ may intervene in accordance with the Content and Moderation Policy.

8.3. No automated decisions with legal effects. Moderation operates as an assisted filter with human control and does not constitute an automated individual decision with significant legal effects within the meaning of Article 22 of the GDPR.

09

Secure development

9.1. Development lifecycle. Atbion OÜ applies secure development practices throughout the software lifecycle, including code review and automated testing before going into production.

9.2. Dependency management. Third-party dependencies are managed and monitored in order to detect and remediate known vulnerabilities in a timely manner.

9.3. Security testing. Atbion OÜ carries out security testing periodically, including vulnerability assessments and penetration testing (pentests), and prioritises the remediation of the findings according to their severity.

9.4. Error tracking. Atbion OÜ uses Sentry for error and performance tracking, minimising the personal information included in the diagnostic logs.

10

NIS2 posture

10.1. Directive (EU) 2022/2555 (NIS2) establishes measures for a high common level of cybersecurity in the European Union.

10.2. Atbion OÜ periodically assesses whether the Platform falls within the scope of NIS2 and of its transposition into Estonian law. Regardless of the outcome of that assessment, Atbion OÜ aligns its technical and organisational measures with the best practices that inspire NIS2 —among them risk management, supply chain security, incident response and business continuity— as part of its general security commitment.

11

Responsible vulnerability disclosure

11.1. Atbion OÜ welcomes the collaboration of the security community. If you detect a possible vulnerability in the Platform, we ask you to report it responsibly and privately to security@votinova.com, providing sufficient information to reproduce it.

11.2. We ask you not to publicly disclose the vulnerability until Atbion OÜ has had a reasonable opportunity to analyse and remediate it, and not to access third-party data or degrade the service during your testing. Atbion OÜ undertakes to handle the reports in good faith and not to take legal action against those who research responsibly and proportionately.

12

Customer security responsibilities

Security is a shared responsibility. The Customer and the Users of their Organisation must:

12.1. Use strong and unique passwords for their Votinova account and not reuse them on other services.

12.2. Activate two-step verification (2FA), especially on accounts with administration or billing privileges.

12.3. Maintain the custody of their credentials and of their devices, not share their access and promptly notify Atbion OÜ of any unauthorised use through hello@atbion.com.

12.4. Diligently manage the roles and invitations within their Organisation, removing access that is no longer necessary.

12.5. Where they act as controller of their Participants' data, configure the participation mode (anonymous, identified or authenticated) in accordance with their legal basis and their instructions, as set out in the Data Processing Agreement.

13

Contact

Atbion OÜ — Estonian Commercial Register 16890390 — VAT EE102728154 — Votinova (votinova.com).

Päivitetty viimeksi: 18 June 2026

Atbion OÜ — Votinova (votinova.com)