Encrypted connections In place
Every connection uses TLS 1.2 or newer with strict transport security. Traffic passes a managed web proxy, and the server refuses requests that do not come through it.
This page says what is in place today and, just as plainly, what we are finishing before any Amazon account is connected. The current pilot uses sample data and holds no Amazon data and no Amazon access tokens.
Every connection uses TLS 1.2 or newer with strict transport security. Traffic passes a managed web proxy, and the server refuses requests that do not come through it.
A host firewall is active, the database accepts local connections only, and password login to the servers is disabled: access is by SSH key only.
Server access is limited to the DigitEMB owner and the engineering team he authorises. Secrets files are readable by the system administrator only and are never written to logs.
Each sign-in uses a one-time six-digit code sent to your e-mail. It works for 10 minutes, allows five tries, and you can ask for five codes an hour. Codes and invitation links are stored only as hashed values.
Session cookies are HttpOnly and Secure and expire after 14 days. Actions inside your workspace are protected against cross-site request forgery, and pages send strict security headers.
The service has its own database and database login, separate from DigitEMB's other systems, and runs under a restricted account with limits on memory and processes.
Nightly database backups are kept for 14 days, and we have tested restoring one.
Automatic operating-system security updates are enabled and applied. Repeated failed logins are blocked at the host, and web access and sign-in activity are logged.
We do not ask Amazon for buyer names, addresses or e-mail addresses.
Your data stays in your own workspace, is never combined with another seller's and is never sold. It is deleted when you ask, within the periods in our privacy policy.
| What | Where and who |
|---|---|
| Servers and database | Hosted by DigitEMB's cloud provider, DigitalOcean, in Bangalore, India |
| Web traffic | Passes Cloudflare before reaching the servers |
| E-mail delivery (sign-in codes, invitations) | Amazon Web Services e-mail service |
| Fonts on public pages | Google Fonts, which receives a browser request when the fonts load |
If the servers move to another region or provider, this page and the privacy policy are updated first.
The pilot holds no Amazon data and no access tokens, so these items are not needed for it. They are what we are completing before account connections are introduced.
The planned Amazon connections must meet Amazon's Acceptable Use Policy and Data Protection Policy and receive Amazon's approval before they are offered.
Write to support@digitemb.com with the word "Security" in the subject. Describe what you saw and where. Please do not access other people's data while checking, and give us a reasonable time to fix a problem before you share it. We answer on working days, Monday to Friday.