// SECURITY · PRIVACY

    Security & privacy

    You can't afford approximation. Neither can we.

    Security consultants can't hand their clients' vulnerabilities to a careless platform. Dossier is built so your engagement data is minimised, encrypted, hosted in the EU and deleted on a schedule, and so nothing you upload is ever used for anything but your report.

    // 01

    Your data stays yours

    Uploaded scan files are deleted as soon as the report is generated. Finished reports are kept 30 days so you can download them, then permanently erased. We never resell, share or repurpose your data.

    // 02

    EU hosting

    Application, database and file storage run entirely within the European Union. Your client data never leaves the EU.

    // 03

    No training on your data

    No client scan, finding or report is ever used to train a model. Your engagements stay confidential.

    // 04

    Anonymisation honoured

    Normalise IPs and hostnames upstream if you wish; Dossier honours the input and never tries to re-identify it. Reports can also anonymise client identifiers automatically.

    // 05

    Encryption

    TLS 1.2+ in transit, AES-256 at rest. Signed, expiring download links for every report.

    // 06

    Access control

    Row-level security isolates every account: a user can only ever see their own reports and findings, enforced at the database, not just the interface.

    // 07

    GDPR by design

    GDPR-aligned by design: EU residency, data minimisation and scheduled deletion. A data processing agreement (DPA) is available on request.

    // 08

    Confidential by default

    Reports are private, indexed nowhere and served only over signed links. The application pages are excluded from search engines.

    EU-hosted, GDPR-aligned handling of your engagement data

    Dossier processes penetration-test and vulnerability-scan data for security firms, so confidentiality is the product, not a feature. All infrastructure, application, PostgreSQL database and file storage, is hosted in the European Union, and client data never leaves it.

    Uploaded scan files (Nmap, Nessus, Trivy, Nuclei, Burp, ZAP and others) are deleted immediately after a report is produced. Generated reports are retained for 30 days for download and then permanently erased. Data is encrypted in transit with TLS and at rest with AES-256, and every download uses a signed, expiring link.

    Access is isolated per account with database row-level security, no client data is used to train any model, and the platform is GDPR-aligned with a DPA available on request. You can also anonymise IPs and hostnames before upload, Dossier honours the input exactly as supplied.

    Sécurité, hébergement UE et RGPD