Security and privacy

Describe safeguards specifically instead of making blanket promises

GHSDoku separates tenants, roles and storage scopes technically. The infrastructure and data location used for the cloud service are defined in the applicable contract.

Hosting model and location

The cloud provider, region, data location and data processing terms are defined contractually. The specific information depends on the production environment in use.

Encrypted transport

Production instances are designed for HTTPS with secure cookies and HSTS. TLS termination is provided by the reverse proxy or ingress.

Roles and permissions

Platform role, customer membership, company roles and rights for sites, storage locations and work areas are checked separately.

Backup and recovery

Database and PDF storage are backed up separately. Operations documentation covers backup, restore, migration and rollback; operators must test recovery regularly.

Logging

Security-relevant and business actions are logged with context. Credentials, tokens and full payment data do not belong in application logs.

Tenant separation

Data access is restricted to customer and company context. Shared substances are exposed only through explicitly configured relationships.

Data-conscious processing

The application processes user, organisation and domain data for its functions. When billing is enabled, payment data is processed by Stripe and card details are not stored in GHSDoku.

Responsibility boundaries

The software is not a certification or legal guarantee

GHSDoku is a tool for structured documentation. Correct classification, completeness, currency, risk assessment and compliance with operational or legal duties still require professional review. Certifications are mentioned only when they are demonstrably valid for the specific service.

Next step

Bring hazardous substance data together from scattered sources

Use your own sites and documents to assess whether GHSDoku fits your processes.