Security
Urna holds your risk data — a list of what could hurt your organisation — so it should be candid about how that data is protected. Here's the real posture, including the gaps.
What's in place
- Hosting in London (Fly.io, UK/EU region). Traffic is served over TLS; HSTS is enforced.
- Encryption at rest for sensitive identity fields (emails, two-factor secrets) using Fernet; passwords are bcrypt-hashed.
- Daily encrypted backups with a fixed retention window.
- Two-factor authentication available on every account and required for platform administrators, with lockout and single-use (replay-burn) protection.
- Append-only audit logging of privileged actions and data exports; IP addresses are never stored in the clear — only as keyed (HMAC) fingerprints.
- Workspace isolation: personal workspaces are visible only to you; organisation workspaces only to that org's active members. Platform admins get no read bypass to your working data.
- No third-party trackers or analytics on the marketing or app pages.
- Your data is exportable at any time (CSV / zip), and your account is deletable.
What isn't there yet — stated plainly
- No SOC 2 or ISO 27001 certification. Planned if and when we take on enterprise customers; it's the wrong spend for a free tool today.
- No SSO / SAML. On the roadmap for organisation plans; email + password with 2FA for now.
- Single-region, single-instance architecture. Simple and auditable, but it means a recovery-point objective of up to 24 hours and no multi-region failover yet.
- No independent penetration test yet. Planned.
Reporting a vulnerability
Please email security@urna.cloud. We welcome good-faith disclosure and won't pursue researchers who act responsibly and avoid privacy violations or service disruption.
Sub-processors & data handling
See the Data Processing Agreement for the sub-processor list and processing terms, and the privacy policy for how personal data is handled.