Security Policy
Last updated: May 16, 2026 (Effective date)
On this page
This Security Policy describes the technical and administrative safeguards that protect Data Subjects' personal data and user content stored in the Servan service.
1. Transport security
- All client-server traffic is encrypted with TLS 1.2 or higher.
- HSTS (HTTP Strict Transport Security) is enforced.
- Certificates issued by a public CA and rotated regularly.
2. Encryption at rest
- Cloud SQL (PostgreSQL): at-rest encryption with Google Cloud KMS.
- Firestore: platform-level encryption.
- Cloud Storage: object-level KMS encryption.
- Backups: encrypted with the same KMS keys.
3. Authentication and access control
- User authentication via Firebase Authentication.
- Social login: Google, Apple, GitHub.
- 2FA available through upstream identity providers.
- Backend operator access: least-privilege IAM, VPC isolation, audit logs.
- OAuth tokens: scoped per team and protected by database-level encryption.
4. Backups and recovery
- GCP automated backups (daily snapshots).
- Backup retention: 30 days.
- Disaster recovery: multi-zone replication (asia-northeast3).
- Recovery Time Objective (RTO): within 4 hours.
- Recovery Point Objective (RPO): within 24 hours.
5. Monitoring and audit
- Full request logging via Cloud Logging.
- Administrator access auditing via Cloud Audit Logs.
- Crash detection via Firebase Crashlytics.
- Automated detection of anomalous traffic patterns.
6. Incident response
In case of a security incident we follow this procedure:
- Step 1: Detection (automated alarms or manual reports).
- Step 2: Containment and impact assessment (within 12 hours of detection).
- Step 3: Notify affected Data Subjects and the supervisory authority (within 72 hours of detection).
- Step 4: Root-cause analysis and corrective measures.
- Step 5: Post-mortem publication (where appropriate).
7. Responsible disclosure
If you discover a security vulnerability, please report it via the procedure below. We thank responsible reporters and will not take legal action against good-faith research.
- Report to: support@tyrannoapartment.com
- Subject: [Security] Vulnerability report
- Include: description, reproduction steps, impact, PoC (if available)
- Our response: acknowledge within 3 business days; analysis result within 14 days
- Please refrain from public disclosure until a patch is available
8. Compliance
- PIPA (Republic of Korea Personal Information Protection Act)
- GDPR (EU General Data Protection Regulation)
- CCPA/CPRA (California)
- Operated on GCP/Firebase infrastructure with SOC 2 Type II and ISO 27001 certifications
9. Security hardening roadmap
Planned improvements on our roadmap:
- Column-level encryption for OAuth tokens (currently DB-level encryption is applied).
- Self-attested SOC 2 certification.
- Bug bounty program.
- Hardware security keys (WebAuthn/FIDO2).
10. Contact
General: support@tyrannoapartment.com
Security disclosure: support@tyrannoapartment.com (subject [Security])
Note: This document is provided as general guidance. For specific legal advice, please consult a qualified attorney.