Ochroni security
Security and Procurement Pack
This page lists current facts for buyers and vendor review teams. It covers Ochroni security, privacy, hosting, subprocessors, support contacts, and assurance scope.
This is a factual due diligence pack. It is not a certification, legal opinion, or external audit report.
Company scope
Piotr Ciechowicz operates Ochroni in Berlin as a B2B incident-management SaaS. Ochroni has no consumer product.
Data scope
In the standard service, Ochroni does not intentionally handle special-category data, criminal-offence data, children's data, or raw payment card numbers. In the standard service, Ochroni does not handle customer incident data for AI or LLM use.
Procurement contact
Security reviews: [email protected]
Legal and privacy: [email protected]
Review materials
This page collects hosting, subprocessor, DPA, security control, and support contact information for vendor review.
Current assurance status
RPO is the target data loss window. RTO is the target restore time. An SLA is a contractual service commitment.
| Topic | Current fact | Qualification |
|---|---|---|
| Hosting region | Ochroni runs its public SaaS deployment on Railway in an EU region. | Confirm the production URL and region in the order form. |
| Backup and restore | RPO sets the target data loss window. The target is 15 minutes. RTO sets the target restore time. The target is 60 minutes. These are operational targets. They are not SLA commitments unless the contract states them. | Ochroni describes backup and restore procedures. This public pack includes no third-party restore report. |
| Monitoring | Ochroni checks query health endpoints for web, worker, scheduler, and Spacetime. | Ochroni describes these service health checks for vendor review. |
| Support contacts | Ochroni publishes [email protected], [email protected], and [email protected] as intake addresses. | Use the address that matches your request. |
| Assurance status | Ochroni does not claim ISO 27001, SOC 2, NIS2, KRITIS, or similar certification. | This pack lists controls and procurement information for buyer review. |
Security controls
- Private tables hold operational data. Server paths apply workspace and role checks before they expose data or accept writes.
- Ochroni checks the session before it issues a realtime token. The current tab stores each token for up to 15 minutes.
- The public self-serve plan does not include MFA, SSO/SAML, or SCIM.
- The edge limits public Spacetime access. Database management and administrative routes are not public.
- The initial self-serve plan has no customer-facing outbound integration settings.
- Password reset audit records store a non-reversible token reference. They do not store token material.
Legal and privacy documents
| Document | Use |
|---|---|
| Terms of Service | B2B service terms with German binding text and an English convenience translation. |
| Privacy Policy | Controller and processor roles, purposes, retention, rights, subprocessors, and contacts. |
| Data Processing Agreement | The DPA sets processor duties, technical and organisational measures, subprocessors, transfer safeguards, and return or deletion handling. |
| Cookie and Browser Storage Notice (legal document) | Necessary browser storage, consent-gated Google Analytics, withdrawal, and retention. |
| Impressum | German provider identification and contact information. |
Subprocessors
A subprocessor handles customer data for Ochroni within a defined service scope.
| Vendor | Status | Role | Scope note |
|---|---|---|---|
| Railway | Active hosting | Railway hosts web, worker, scheduler, and Spacetime. It also stores runtime records and operational metadata. | Ochroni describes hosting, runtime, and region information for buyer review. |
| Stripe | Active for paid billing | Stripe handles billing, checkout, customer portal, invoices, and billing events for paid billing. | Customer and order details determine taxes, invoices, and Reverse Charge treatment. |
| Mailgun/Sinch | Active email | Mailgun/Sinch handles transactional email for invites, password resets, operational notices, and billing or support messages. | Ochroni uses Mailgun's EU API endpoint for transactional email. |
| Sentry | Active diagnostics | Sentry monitors errors and provides technical diagnostics for application stability. | Ochroni restricts personal data transmission. Technical error context can include limited identifiers or route details. |
| Google Ireland Limited | Analytics consent | Google Ireland Limited receives Google Analytics 4 data for public marketing pages after analytics consent. | Ochroni blocks the Google tag before opt-in. It does not use the tag for app or customer workspace data. |
Current scope and assurance status
- Ochroni is a B2B SaaS service for logistics and supply chain incident response.
- Ochroni is not an emergency service or a substitute for statutory reporting, legal advice, or customer procedures.
- Ochroni does not claim ISO 27001, SOC 2, NIS2, KRITIS, or equivalent certification.
- Ochroni does not claim NIS2 or KRITIS regulated-entity status. Customers with NIS2, BSIG, or KRITIS duties may contact Ochroni for security, subprocessor, incident-response, and continuity material for supplier-risk review.
- The public self-serve plan does not include SSO/SAML, SCIM, MFA, or external penetration-test reports. Buyers can discuss extended assurance material for larger deployments.
- Ochroni records incident events, timestamps, ownership, participation, and audit records. Customers remain responsible for employee notices, works-council, labor-law, and internal-policy checks before use.
- This page lists backup, recovery, monitoring, hosting, subprocessor, DPA, security control, and support contact information.
- Send additional vendor review questions to [email protected] or [email protected].
Legal, privacy, DPA, and controller questions: [email protected]
Security questionnaires and disclosure reports: [email protected]
Read the Security Overview and Legal Center for linked source documents.