Data Security
LiteLog stores all data exclusively in Frankfurt (Germany), protects it with end-to-end encryption, and guarantees 99.99 % availability. Daily backups and audited compliance standards (including SOC 2 Type II and GDPR) shield you from data loss and legal risks.
Why data security is essential for LiteLog
As a platform for process and time documentation, LiteLog processes personal, location, and performance data. An uncompromising security concept ensures legal compliance, high availability, and your customersโ trust.
1 Hosting location: Frankfurt / Germany
LiteLog runs on german Servers (Frankfurt). Production and backup data never leave Germany and are directly subject to the BDSG and the GDPR.
2 Encryption
| Layer | Technology | Purpose |
|---|---|---|
| In transit | TLS 1.2 / 1.3 | Protects against eavesdropping and tampering |
| At rest | Full-disk encryption | No access even in case of hardware theft |
| Backups | Encrypted snapshots | Restore without exporting data |
Passwords are hashed with bcrypt. Sensitive tokens are additionally protected with AES-256.
3 Application security
- Role-based access control โ granular permissions per module
- Strong password policies & reCAPTCHA protection
- Session time-outs & device binding for mobile logins
- Audit logs โ every critical action is traceable
- Regular penetration tests by independent specialists
4 Audit trail: changes stay traceable
For damage claims, insurance cases and audits, it is not enough that something was documented โ the documentation must be tamper-evident. LiteLog therefore records not only results, but their history:
- The original is preserved โ subsequent changes to recorded times and patrol records create their own history entries; the original state is never overwritten.
- Who, when, why โ every history entry carries the user and a server-side timestamp; editing or deleting recorded times and patrol records requires a stated reason.
- Deletions leave traces โ audit entries are decoupled from the source record and are not removed when related data is deleted; sites with documented history are archived instead of deleted.
- Submitted forms are immutable; reports are generated as PDF/A (ISO 19005) for audit-proof long-term archiving.
- No automatic expiry โ change audits are not purged automatically and remain available for the duration of the contract.
So even years later you can answer: who completed a task and when, what was originally entered, whether a record was changed later โ and by whom.
5 Redundancy & backups
- Automated snapshots at least once daily (up to 3ร on higher plans)
- Retention: 30 days + 11 monthly roll-ups
- RPO / RTO: โค 24 h / โค 4 h
- Multiple copies within the Frankfurt cluster
6 Compliance & audits
- SOC 2 Type II โ international standard for security and availability controls
- PCI DSS Level 1 โ secure credit-card processing (for payment features)
- GDPR / BDSG โ data-processing agreement (DPA) available
All certifications apply to the Platform.sh layer and are fully inherited by LiteLog.
Data integrity per ALCOA+
LiteLog documents according to the ALCOA+ data integrity principles (Attributable, Legible, Contemporaneous, Original, Accurate โ plus Complete, Consistent, Enduring, Available):
- Every action is unambiguously attributed: person, server-side timestamp, place/area
- Entries are never overwritten โ corrections create new records with a mandatory change reason
- Histories are preserved permanently and exportable as audit-ready PDF reports
See the ALCOA+ glossary entry for details.
7 Availability & DDoS protection
- 99.99 % SLA on production environments
- Auto-scaling during traffic peaks
- Layer 3โ7 DDoS mitigation (optional add-on)
8 Data export & end of contract
Your data belongs to you. LiteLog is designed so you can build a vendor-independent operational archive:
- Ongoing export: reports and records as PDF/A, lists and evaluations as CSV, machine-readable access via the REST API.
- Automatic dispatch: reports can be sent on a schedule to your own mailboxes or to clients โ your archive grows on its own.
- End of contract: on request you receive a complete export of your data; afterwards the data is deleted in accordance with the DPA.
Documents for your review
Everything your data protection officer, QA or procurement team needs for the supplier assessment โ available immediately, no request required.
