We take the security and privacy of your data on ProductLift seriously. The commitments below are the ones we hold ourselves to contractually: they are mirrored in our Data Processing Agreement, and this page is kept in line with it.
Our engineers have experience working on highly reliable, scalable, and secure systems at global banks and insurance companies. ProductLift is built and operated by Ruby Foundry B.V. in the Netherlands, and everyone with access to production systems is bound by confidentiality obligations.
ProductLift acts as a processor for the personal data your end-users submit to your portal. Our Data Processing Agreement covers processing instructions, sub-processors, international transfers, breach notification, audit rights and the technical and organisational measures we apply. Transfers to US-based providers rely on the EU-U.S. Data Privacy Framework and Standard Contractual Clauses.
ProductLift production services (application servers, primary database, and backups) run on Hetzner Online GmbH infrastructure in Hetzner's data centres in Falkenstein, Germany (EU/EEA). All Controller personal data processed by the ProductLift service is stored inside the EU/EEA.
Hetzner's data centres are ISO/IEC 27001 certified and operate with industry-standard physical access controls: 24/7 on-site staff, video surveillance, biometric and multi-factor access control, access logs, redundant power and cooling, and fire-suppression systems.
File uploads and attachments are stored in the EU-West (Ireland) region of Amazon Web Services S3 via Amazon Web Services EMEA SARL, and delivered through a content delivery network operated by an EU company (Bunny.net, Slovenia).
A full list of third-party service providers that may process personal data on our behalf is available on our Subprocessors page.
All connections to ProductLift use HTTPS with TLS 1.2 or 1.3; older protocols are disabled and there is no non-TLS option. HTTP Strict Transport Security is enforced, and certificates for your portal, including custom domains, are issued and renewed automatically. Traffic between our application and the database runs over TLS on a private network, and connections to our sub-processors for email, storage, AI features and billing are equally encrypted.
Database backups are encrypted with AES-256 before they leave our servers and are held in append-only storage (see Backups below). Sensitive values inside the application, such as two-factor authentication secrets, single sign-on client secrets and the API credentials you connect, are encrypted with the application key. File uploads and attachments are encrypted at rest by AWS S3 and are reachable only over HTTPS.
The database itself is not reachable from the internet: it runs on a separate server on a private network and accepts connections only from the ProductLift application.
Development, testing and production are separate environments. The test suite runs against its own database and never touches production data. Production servers are reached over SSH with key-based authentication only, password login is disabled, and SSH is not exposed to the public internet: it is reachable only through a private device mesh, enforced by the hosting provider's firewall.
Production is monitored continuously for errors, availability and background-job health, with automated alerting when thresholds are exceeded, intrusion blocking on both servers, and a written incident-response runbook behind it.
Every change to ProductLift goes through version control and an automated suite of more than 2,000 tests, including dedicated tests for tenant isolation between portals, two-factor authentication, API token scope and privacy features. Deploys are zero-downtime, and whenever a change touches the database structure an automatic backup is taken first, with the previous release kept for immediate rollback. Dependencies are monitored for known vulnerabilities and production servers install operating-system security updates automatically. Our change-management policy is available on request.
We run an external security review of our public surface, covering TLS configuration, exposed services, HTTP response headers, DNS and certificate transparency, on a quarterly cadence and after every infrastructure change.
Admin accounts can enable two-factor authentication with an authenticator app, recovery codes and trusted devices, or sign in through Microsoft 365 / Entra ID single sign-on restricted to your own tenant, so your organisation's MFA and conditional-access policies apply. Google and GitHub sign-in are also available. Passwords are stored as bcrypt hashes and are never sent by email; account creation and password reset use time-limited links. Login, password-reset and account-change endpoints are rate limited, and every login attempt is recorded with its source address. Your end-users can sign in through single sign-on from your own system, or register on your portal with optional email verification and admin approval.
User data entered on public pages or included in public profile information may be viewed or accessed by anyone. Portals can be made private, end-user names and avatars can be hidden from other end-users, and posting and voting can be anonymous. Data may also be collected, shared, retained, and used as described in ProductLift's Privacy Policy.
User data may be shared by ProductLift with third-party service providers (a recipient's email address with our email delivery provider, for example) as listed on our Subprocessors page. Integrations that you connect with your own credentials (Slack, Jira, Azure DevOps, HubSpot, webhooks, your own email provider) send data to those services on your instruction and are not sub-processing by ProductLift.
The primary database is backed up automatically every day, and again before any deploy that changes the database structure. Backups are encrypted and written to Hetzner Object Storage in Falkenstein, Germany, in a bucket configured with Object Lock in compliance mode: once written, a backup cannot be altered or deleted by anyone, including us, until it expires after 60 days. This protects against ransomware and accidental deletion. Backups are retained for up to 60 days after creation and then expire.
Because backups are immutable, personal data deleted from the live service can persist in a backup until that backup expires. Deletion requests are always carried out immediately on the live service. This trade-off is documented in Annex 3 of our Data Processing Agreement.
File attachments are not included in the database backups and rely on Amazon S3's internal redundancy, which Amazon states provides 99.99% yearly data durability.
Because user data stored in ProductLift is on shared infrastructure, we cannot restore a single customer's data from a backup in isolation. If you need a complete record of your data, use the export functions in the admin area.
Written recovery runbooks cover rebuilding the service from a backup. Our recovery objectives are 4 hours to restore service and at most 24 hours of data loss, and the restore procedure was last exercised during our August 2026 server migration.
If we become aware of a personal data breach affecting data we process on behalf of a customer, we notify the affected customer without undue delay and, where feasible, no later than 48 hours after becoming aware of the incident. This commitment is reflected in Article 9 of our Data Processing Agreement. We have had no personal data breaches to date.
ProductLift does not currently hold SOC 2 or ISO 27001 certification. Our hosting provider (Hetzner) maintains its own certifications, including ISO/IEC 27001. For enterprise reviews we provide a security and compliance pack that maps our controls to ISO/IEC 27001:2022 Annex A, together with our policy documents and a dated remediation plan. If you have specific security requirements or would like to submit a security questionnaire, contact us at [email protected].
If you have any remaining questions or concerns about our security, don't hesitate to contact us.