# Security Overview and Access to the Detailed TOMs Last updated: 2026-09-16 This public overview describes the principles of savien's technical and organisational measures under Art. 32 GDPR. It supports an initial security review without disclosing internal configurations or other information that could facilitate attacks. ## 1. Security Principles - Access to accounts and company data is authenticated and restricted by role. - Permissions follow the principle of least privilege. - Data transmitted between the browser, application and connected services is protected in transit. - Application- and database-level controls separate tenant and storage access. - Security-relevant changes and events are logged to an extent appropriate for their purpose. - Recovery, update and response processes are reviewed regularly and adapted after material changes. - Service providers that may access personal data are assessed contractually and on a risk basis. ## 2. Measure Categories The detailed TOMs address physical and logical access, authorisation, transmission, input, availability and separation controls, as well as processes for permissions, vulnerabilities, security incidents, backups and recovery. Measures are selected and developed taking into account the state of the art, implementation costs, the nature, scope, context and purposes of processing, and risks to data subjects. ## 3. Details Not Published The public overview does not disclose keys or secrets, internal identifiers, network or firewall rules, detailed storage or backup paths, alert thresholds, administrative access information or complete incident playbooks. ## 4. Contractual Annex and Further Evidence The [contractual TOM annex](/en/tom-annex) is available for inspection and download without an account before accepting the DPA. The accepted version is recorded together with the DPA and Subprocessor List. Prospective and existing customers may request further confidential evidence at security@savien.io, stating their organisation, business email address and role. We check authorisation and provide appropriate records through a protected channel. Requests may be made before contract formation. Operational evidence supplements the annex; customer-specific service commitments require express agreement. ## 5. Related Documents - [Data Processing Agreement](/en/dpa) - [Subprocessor List](/en/subprocessors) - Security contact: security@savien.io