HouseID legal centre · G
TECHNICAL AND ORGANISATIONAL MEASURES (TOMs) AND CONTINUITY
Security, operational and organisational measures protecting the service and Client data.
Security governance has an accountable owner, asset and data-flow inventory, information classification, risk register, approved policies, periodic review and expiring exceptions. Duties are mapped to GDPR, contracts and any scope under Czech Act 264/2025; using Cloudflare alone does not establish compliance.
Identity-first controls include unique accounts, MFA for privileged/designated roles, least privilege, separation of owner/CTO/CFO/COO and delegated roles, tenant/project scoping, owner approval, periodic recertification and immediate leaver removal. Privileged actions are logged and critical changes use four-eyes review where appropriate.
Data in transit uses modern TLS and managed D1/R2 storage should be provider-encrypted at rest. Secrets are not held in source code or client browsers and use managed secret storage and rotation. Keys, algorithms, jurisdiction and actual coverage are evidenced by current configuration and supplier documentation before customer claims.
Applications enforce server-side authorisation, tenant isolation, input validation, file size/type limits, safe names and paths, download/delete permissions, CSRF/XSS/injection/SSRF protections and fail-closed behaviour for critical services. Document uploads have checksums, type validation, risk-based malware scanning or quarantine and an audit event.
Development uses change control, review, automated tests, dependency and secret scans, environment separation, minimal production access and a rollback version. Vulnerabilities are risk-classified against internally approved remediation targets. External penetration testing or certification is stated publicly only when actually performed and evidenced.
Logs cover authentication, role changes, sensitive reads/downloads, upload, deletion, export, invitations, implementation handoff, settings and admin actions. Logs minimise content and personal data, are tamper-resistant, time-synchronised, role-restricted, retained and alerted. Monitoring and sentinels must not store Client-document content.
Backups are separated, access-restricted, encrypted, monitored and regularly restoration-tested according to service scope. Binding RPO and RTO are stated in the Order or SLA; without that agreement no specific recovery time is publicly guaranteed. Backup existence alone is not restoration evidence without testing and an accountable owner.
Incident response includes classification, 24/7 intake for critical alerts, roles, escalation, evidence, containment, recovery, legal assessment, communications and post-incident remediation. Every production incident has a timeline and owner. The security contact is info@houseid.cz until a specialised security channel is activated and published.
Continuity identifies critical services, dependencies, manual workarounds, communications, recovery order and scenario tests. Key journeys include public lead and email, invitation, login, sales-case creation, implementation handoff, upload/download/delete/export, notifications, adviser and audit PDF. Sentinels use synthetic data and have failure escalation.
Before onboarding, suppliers are assessed for security, privacy, location, transfers, continuity, subprocessors, audit and exit. Contracts cover confidentiality, incidents, return/deletion, audit and transfer safeguards. Access is removed at exit. Contracting entity, DPA, certifications and subprocessor changes are reverified annually.