Security at Cuigg
How Data Reporter protects the report data organisations trust us with.
Hosting
The service runs on servers in EU data centres (Hetzner). Report data does not leave that environment to third-party analytics or advertising services; there are none on the platform.
Encryption
All traffic is encrypted in transit with TLS. Passwords are never stored, only salted hashes. Sign-in uses secure, HTTP-only session cookies scoped to our domain.
Tenant isolation
Every organisation's workspace is isolated server-side. Requests are scoped to the signed-in account's organisation and fail closed: anything not explicitly attributed to your organisation is withheld. These isolation rules are covered by an automated test suite that runs on every change to the server.
Access control
Client accounts are read-only by design, reports are prepared for you, and nothing a reader does can alter another team's data. Administrative actions (password resets, account changes) are logged. Sign-in attempts are rate-limited to blunt password guessing.
Data lifecycle
Backups are taken routinely and kept only as long as needed for recovery. When a contract ends, workspace data is deleted within 30 days, see the Privacy Policy for the full retention picture.
Reporting a vulnerability
If you believe you've found a security issue, email winnerflags@gmail.com with enough detail to reproduce it. We'll acknowledge within two working days, keep you informed while we fix it, and never take action against good-faith research.