Security

Last updated · 4 June 2026

In short: We take reasonable, industry-standard measures to protect your data — encryption, restricted access, and trusted infrastructure providers. No system is perfectly secure, but security is built into how we work.

This page describes the technical and organisational measures we use to protect personal data, in line with our obligations under the GDPR. It supports our Privacy Policy.

Encryption

  • In transit: data exchanged between you and Tvorya is protected using TLS (HTTPS).
  • At rest: data stored on our infrastructure is encrypted by our cloud providers.

Access control

Access to personal data is restricted on a need-to-know basis, following the principle of least privilege. Only the people and systems that need access to do their job are granted it, and access is protected by authentication.

Trusted infrastructure

We host the Service with established cloud providers that maintain strong physical and operational security controls. Our key providers are listed in our Privacy Policy. Payment-card data is handled by our payment provider — we do not store full card numbers — which reduces the sensitive data we hold.

Secure development

We aim to follow secure development practices, including reviewing changes before they go live and testing in staging environments before release.

Monitoring

We keep logs of system and application activity to help us detect and respond to issues.

Helping us keep Tvorya secure

If you discover a security issue or vulnerability, please report it responsibly through the Help Center so we can investigate. We appreciate the security community's help in keeping Tvorya safe.

A note on limits

While we work hard to protect your data, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. You also play a part — keep your account credentials private and secure.