cuigg Data Reporter

Security at Cuigg

How Data Reporter protects the report data organisations trust us with.

Hosting

The service runs on servers in EU data centres (Hetzner). Report data does not leave that environment to third-party analytics or advertising services; there are none on the platform.

Encryption

All traffic is encrypted in transit with TLS. Passwords are never stored, only salted hashes. Sign-in uses secure, HTTP-only session cookies scoped to our domain.

Tenant isolation

Every organisation's workspace is isolated server-side. Requests are scoped to the signed-in account's organisation and fail closed: anything not explicitly attributed to your organisation is withheld. These isolation rules are covered by an automated test suite that runs on every change to the server.

Access control

Client accounts are read-only by design, reports are prepared for you, and nothing a reader does can alter another team's data. Administrative actions (password resets, account changes) are logged. Sign-in attempts are rate-limited to blunt password guessing.

Data lifecycle

Backups are taken routinely and kept only as long as needed for recovery. When a contract ends, workspace data is deleted within 30 days, see the Privacy Policy for the full retention picture.

Reporting a vulnerability

If you believe you've found a security issue, email winnerflags@gmail.com with enough detail to reproduce it. We'll acknowledge within two working days, keep you informed while we fix it, and never take action against good-faith research.