Security & Compliance

Security and data protection are core to how we build and operate wservices. This overview summarises our practices and the documents that govern them.

Data protection & GDPR

We process personal data in line with the EU GDPR, the Swiss DPA/revDPA. Our data-processing terms, technical measures and sub-processors are fully documented and public.

Encryption

Traffic is encrypted in transit (TLS, with one-click Let’s Encrypt certificates for hosted sites). Office devices and drives holding personal data are encrypted at rest.

Access control

Customer passwords for SSH, mail and the control panel are not known to us. Administrative access follows least-privilege with a revision-proof authorization process for staff.

Backups & resilience

Daily backups to physically separate systems, disk mirroring on relevant servers, UPS/emergency power and 24/7 monitoring with a defined escalation chain.

Responsible disclosure

We run a bug bounty program and welcome coordinated vulnerability reports. Good-faith research under our rules is protected by safe-harbor terms.

Report a security issue

Found a vulnerability? Please contact our security team — see the bug bounty program for scope and rewards.

security@wservices.ch