Skip to main content

Security

Last updated: May 2026

Our posture

Agata Hexe Studio is a small independent software studio. We don't treat security as a marketing line — we treat it as a precondition for shipping. This page documents what we do today. If something on the list looks incomplete to you, it probably is; tell us.

Infrastructure

• Hosting: Firebase App Hosting (Google Cloud, us-central1 region, United States). HTTPS-only with HSTS preload. • Database: Cloud Firestore (Google Cloud, nam5 multi-region, United States) with encryption at rest. • CDN & edge: Cloudflare (DNS, CDN, and WAF) fronts all traffic; static application assets are served from Cloudflare R2. • Email: Google Workspace Gmail API (transactional + confirmation), sent via a dedicated backend service. SPF + DMARC + DKIM on agatahexe.com. • Bot protection: Cloudflare Turnstile (privacy-preserving, no fingerprinting). • Payments: Paddle as Merchant of Record — we never touch card data (PCI DSS scope = SAQ-A).

Data location & international transfers

Our hosting and database run in Google Cloud regions located in the United States. Because this involves transferring personal data outside the EU/EEA, we rely on appropriate safeguards under Chapter V GDPR: Google LLC is certified under the EU–U.S. Data Privacy Framework, and transfers are additionally covered by the Standard Contractual Clauses incorporated into Google's Cloud Data Processing Addendum. Cloudflare (CDN, edge, and R2 object storage) acts as a processor under its own Data Processing Addendum, which also incorporates the Standard Contractual Clauses.

Application security

• Strict Content-Security-Policy, X-Frame-Options: SAMEORIGIN, and related headers on every response. • Input validation + output escaping on every form. • Honeypot fields on public forms; Cloudflare Turnstile on the contact form. • Dependencies are audited automatically. Critical CVEs are triaged on discovery and patched as soon as reasonably possible, prioritizing issues with active exploitation or direct impact on user data. • No passwords stored on agatahexe.com (no user accounts today). If introduced, bcrypt/argon2 + MFA.

Operational security

• Multi-factor authentication (TOTP, not SMS) on every admin-tier account: hosting, domain registrar, email, cloud, stores. • Principle of least privilege on cloud IAM. • Secrets stored in provider-managed environment variables, never committed to git. • Off-site repository mirrors and scheduled database exports.

Incident response

If we detect or are notified of a breach affecting personal data, we follow a documented runbook with the goal of notifying the competent supervisory authority (LfDI NRW) within 72 hours, as required by Article 33 GDPR. Affected users are informed without undue delay when the breach presents a high risk to their rights.

Reporting a vulnerability

If you believe you've found a security issue in agatahexe.com or any software we ship, please email us at [email protected]. Please do not publicly disclose the issue until we've had a chance to investigate. • Machine-readable: /.well-known/security.txt • We aim to acknowledge reports within 5–10 business days and will keep you posted as we investigate. Response times may be longer during holidays or peak periods.

Scope limitations

We are a micro-entity (sole proprietor, <10 people, <2M EUR turnover) and therefore fall below NIS2 thresholds. We adopt NIS2-adjacent practices voluntarily where cost-reasonable. We are not SOC 2 / ISO 27001 certified.