Security and trust

Security & Data Protection

This page describes the platform security posture, implemented controls, operational practices, and the direct contact path for responsible disclosure or privacy-related security questions.

Trust posture

Implemented, in progress, planned

No fake certifications, no invented uptime numbers, and no claims beyond what the product and operations can actually support today.

The legal and policy information on these public pages should be kept aligned with the current company registration, tax treatment, support workflow, payment setup, and applicable regulatory obligations.

Entwickelt in Deutschland

Fahrnex ist für Fahrzeugbetrieb, Abrechnungsklarheit und Datenschutzanforderungen in Deutschland ausgelegt.

Entwickelt für EU-Datenschutz-Erwartungen

Öffentliche Vertrauenselemente, Rechtstexte und Einwilligungssteuerung sind mit DSGVO-orientierter Transparenz formuliert.

Early-Access-Nutzer

Wir kommunizieren ehrlich, was schon live ist, was verbessert wird und was operativ noch weiter ausgebaut werden muss.

Fahrzeugdaten bleiben organisiert und geschützt

Dokumente, Erinnerungen, Ausgaben und Servicehistorie bleiben in einem strukturierten Arbeitsbereich statt in verstreuten Postfächern und Ordnern.

Authentication and session security

Authenticated areas are protected with Laravel-backed auth, secure session handling, and verified access paths for sensitive product actions.

Implemented
Protected app and billing endpoints
Email verification flows
Role-aware admin access

Encryption and protected storage

Vehicle documents use private access flows, and selected connection credentials are stored with encrypted model casts.

Implemented
Private document preview and download
Encrypted telemetry connection tokens
Sensitive log redaction support

Audit and activity history

Administrative changes and operational actions are recorded so support, finance, and system changes can be reviewed later.

Implemented
Admin audit logs
Support and billing history
Reminder and notification history

Backups and recovery readiness

Backups and recovery procedures are treated as an operational responsibility, but public customer-facing recovery documentation is still being expanded.

In progress
Operational backup routines
Recovery process documentation improving
Customer-facing backup visibility still limited

Infrastructure reliability

The platform already monitors operational health, while public status communication and reliability reporting remain on the roadmap.

In progress
Operational monitoring available
Public status visibility planned
No fake uptime claims

Responsible disclosure and contact

Security and privacy questions can already be routed through direct contact channels while a fuller disclosure workflow is prepared.

Planned
Security contact available
Disclosure workflow page planned
Public reporting process to be formalized

Data protection overview

Privacy-first design

Legal, privacy, and consent pages are part of the public product surface instead of hidden after sign-up.

Access controls

Billing, admin, and stored documents are routed through authenticated and user-scoped endpoints.

Activity history

Audit logs and operational history help make support and admin actions more accountable.

Reliability roadmap

Public status visibility and customer-facing recovery communication are being expanded carefully rather than improvised.

Related trust and product pages