Security & privacy
You can't afford approximation. Neither can we.
Security consultants can't hand their clients' vulnerabilities to a careless platform. Dossier is built so your engagement data is minimised, encrypted, hosted in the EU and deleted on a schedule, and so nothing you upload is ever used for anything but your report.
Your data stays yours
Uploaded scan files are deleted as soon as the report is generated. Finished reports are kept 30 days so you can download them, then permanently erased. We never resell, share or repurpose your data.
EU hosting
Application, database and file storage run entirely within the European Union. Your client data never leaves the EU.
No training on your data
No client scan, finding or report is ever used to train a model. Your engagements stay confidential.
Anonymisation honoured
Normalise IPs and hostnames upstream if you wish; Dossier honours the input and never tries to re-identify it. Reports can also anonymise client identifiers automatically.
Encryption
TLS 1.2+ in transit, AES-256 at rest. Signed, expiring download links for every report.
Access control
Row-level security isolates every account: a user can only ever see their own reports and findings, enforced at the database, not just the interface.
GDPR by design
GDPR-aligned by design: EU residency, data minimisation and scheduled deletion. A data processing agreement (DPA) is available on request.
Confidential by default
Reports are private, indexed nowhere and served only over signed links. The application pages are excluded from search engines.
EU-hosted, GDPR-aligned handling of your engagement data
Dossier processes penetration-test and vulnerability-scan data for security firms, so confidentiality is the product, not a feature. All infrastructure, application, PostgreSQL database and file storage, is hosted in the European Union, and client data never leaves it.
Uploaded scan files (Nmap, Nessus, Trivy, Nuclei, Burp, ZAP and others) are deleted immediately after a report is produced. Generated reports are retained for 30 days for download and then permanently erased. Data is encrypted in transit with TLS and at rest with AES-256, and every download uses a signed, expiring link.
Access is isolated per account with database row-level security, no client data is used to train any model, and the platform is GDPR-aligned with a DPA available on request. You can also anonymise IPs and hostnames before upload, Dossier honours the input exactly as supplied.