Legal sources
Controller: CLARYEL S.R.L.S., 22073 Fino Mornasco, Como, Italy, P.IVA 04258140138, amministrazione@claryel.it. Box consumer sales at the published 99 EUR offer also follow D.Lgs. 206/2005. DSA hosting-platform duties are out of scope until a public forum is offered.
Security policy (public)
Version: 2026-09-02.1
Effective: 2026-09-02
Controller: CLARYEL S.R.L.S., 22073 Fino Mornasco (Como), Italy, P.IVA 04258140138, amministrazione@claryel.it.
This public summary describes organisational and technical measures (GDPR Art. 32). It is not a penetration-test report and does not guarantee absolute security.
Measures
- TLS in transit;
__Host-cookies; CSRF origin checks on state-changing APIs. - Passwords hashed with a dedicated hasher worker; password hashes are never returned in public or admin JSON.
- Session tokens stored as hashes; logout and soft-delete revoke identity, site and legacy sessions.
- Cloudflare Workers + WAF + Turnstile for abuse control.
- Role flags (
is_admin,is_support,is_investor,is_business_admin) independent of marketingrole. Last active administrator cannot be dropped. - D1 access limited to the Worker; no public SQL.
- Operational logs retain hashed network fingerprints, not raw IP, in the admin activity journal.
- Backups and retention: see internal logging policy. Accounting records follow Italian law.
Vulnerability reports
Email amministrazione@claryel.it. Do not request exploit details in public issues.
Related
Internal: internal/information-security.md, internal/incident-response.md. Privacy: /legal/privacy/.