Security Centre
How we protect Scoringmy's infrastructure, data and access. Technical documentation for security, IT and compliance teams.
Data hosted in the EU
Infrastructure at Hetzner (Germany). No international data transfers in the core infrastructure.
Encrypted in transit end to end
HTTPS with TLS 1.2/1.3 across all communications, enforced at the Cloudflare layer.
Professional data only
We process no special categories of data. Name, work email, job title and public LinkedIn metrics.
Daily backups
Automated backups, stored separately from production, with multiple recovery points.
Continuous monitoring
Real-time logging and anomaly detection across activity, performance and errors.
Role-based access control
RBAC with least-privilege enforcement. Each user accesses only what their role requires.
Contents
- Scope of this document
- Nature of the data processed
- Platform architecture
- Encryption and data protection
- Access control
- Logging and monitoring
- Backup and recovery
- Vulnerability management
- Security incident management
- Providers and sub-processors
- Data retention and deletion
- Legal bases and processing roles
- Data subject rights
- Regulatory compliance
- Continuous improvement
- Security policies
- Security FAQs
1. Scope of this document
This Security Centre describes the technical and organisational measures that PeopleXBrand Aceleradora S.L. applies within the Scoringmy platform to protect the confidentiality, integrity and availability of data.
It is intended for information security, IT, legal and compliance teams evaluating Scoringmy as a supplier. For detail on the use of artificial intelligence, see our AI Usage and Transparency page.
2. Nature of the data processed
Scoringmy processes professional data only:
- First name and surname
- Email address
- Job title
- Company or organisation
- Public professional profile URL
- Professional digital presence metrics derived from publicly available information
The platform does not process special categories of personal data (health, ethnic origin, religious beliefs, sexual orientation, biometric data or similar) within the meaning of Article 9 of the GDPR.
2.1 Source of the data
- Information provided directly by registered users.
- Employee email addresses provided by the client company.
- Professional information published on publicly accessible sources, such as LinkedIn profiles.
Scoringmy does not scrape LinkedIn and does not automate user behaviour on the platform.
3. Platform architecture
The architecture follows a reverse-proxy model: all inbound traffic is routed through Cloudflare before reaching the application servers, which prevents the origin infrastructure from being exposed directly to the internet.
Infrastructure hosted at Hetzner Online GmbH (Germany, EU). The origin layer is never exposed directly to the internet.
3.1 Components
| Layer | Function | Provider |
| Perimeter | Reverse proxy, WAF, DDoS mitigation, bot filtering and TLS termination | Cloudflare |
| Application | Frontend, backend, business logic and service orchestration | Hetzner (Germany) |
| Data | Database, file storage and backups | Hetzner (Germany) |
4. Encryption and data protection
4.1 Encryption in transit
All communications with the platform are protected using HTTPS with TLS 1.2/1.3, enforced at the Cloudflare layer. This covers:
- Communications between the user and the platform.
- API calls between the backend and external services.
- Communications with AI model providers.
4.2 Encryption at rest
Stored data is protected using the infrastructure-level security controls provided by the hosting provider.
4.3 Data segregation
Separation between clients is enforced logically at application level through access control mechanisms. The system is designed so that each client can access only their own data and their own workspace.
5. Access control
The platform implements role-based access control (RBAC) with centralised authorisation logic in the backend, ensuring consistent enforcement across all modules.
5.1 Roles
| Role | Scope |
| Admin | Full access to platform functionality, including user management and system configuration. |
| Employee | Restricted access, limited to their own data and specific features. |
5.2 Authentication
- Access to the platform is restricted to authenticated users.
- Authentication via email and password, with secure session management.
- Optional authentication through third-party providers (e.g. Google Sign-In).
- Administrative access is limited to authorised personnel.
5.3 User lifecycle
- Access is granted on the basis of business need.
- Permissions can be modified or revoked at any time.
5.4 Principle of least privilege
Access to production systems is restricted under the principle of least privilege. Only authorised technical personnel with a justified business need can access the infrastructure or the data.
6. Logging and monitoring
The platform implements centralised, real-time logging and monitoring.
| Aspect | Description |
| Scope | Application activity, system performance, database operations and errors. |
| Detection | Identification of abnormal patterns, supporting timely investigation and response. |
| Review | Dashboards and logs are reviewed on a regular basis to identify anomalies, performance issues or potential security events. |
| Personal data | Logs do not include sensitive personal data. |
7. Backup and recovery
7.1 Strategy
- Full daily backups, executed automatically on a scheduled basis.
- Scope: production environment, application data, system configurations and infrastructure.
7.2 Storage and retention
- Backups are stored securely within the hosting infrastructure, separately from the production environment.
- Retention on a rolling basis, maintaining multiple recovery points.
- Access to backup systems is restricted to authorised technical personnel through secure authentication mechanisms.
7.3 Recovery capability
Backups allow the application environment and its associated data to be restored in the event of:
- System failure
- Data corruption
- Operational incidents
- Accidental data loss
7.4 Validation
Backup processes are monitored to verify successful execution. System logs allow backup activity to be audited, and any issues detected are reviewed and addressed.
8. Vulnerability management
Security is implemented through a layered model:
8.1 Preventive measures
- Cloudflare protection: web application firewall (WAF), DDoS mitigation, and traffic and bot filtering.
- Secure backend architecture: reverse-proxy model, with no direct exposure of the origin infrastructure.
- Regular updates of application dependencies and infrastructure components.
- Periodic review of security configurations.
8.2 Detection and response
- Monitoring and logging tools allow anomalies or unexpected behaviour to be identified.
- Tracking of known vulnerabilities and application of security patches where required.
- Issues identified are reviewed and addressed as part of ongoing maintenance.
8.3 External auditing
Security is currently maintained through continuous internal controls and ongoing monitoring. The introduction of external security audits — including third-party penetration testing — is part of the platform's roadmap, as an element of our continuous improvement programme.
9. Security incident management
In the event of a security incident, Scoringmy follows internal procedures for:
- Investigation of the incident
- Containment of the system
- Mitigation and corrective action
Breach notification
In the event of a security breach affecting personal data, PeopleXBrand will notify the affected client without undue delay and within a maximum of 24 hours of detection, in line with GDPR obligations.
10. Providers and sub-processors
Scoringmy's core infrastructure is hosted within the European Economic Area (EEA). No international transfers of data outside the EEA take place within the core infrastructure.
Certain supporting technology providers may involve international transfers, which are carried out under the safeguard mechanisms set out in the GDPR (standard contractual clauses and equivalent safeguards).
| Provider | Service | Location |
| Hetzner Online GmbH | Infrastructure and hosting (application, database and backups) | Germany (EU) |
| Cloudflare | Reverse proxy, WAF, DDoS mitigation and traffic filtering | Global network · GDPR safeguards |
| Sendinblue (Brevo) | Transactional email delivery | France (EU) |
| ActiveCampaign | Newsletters with product information and updates, where this functionality is enabled during the term of the service | United States · GDPR safeguards |
| OpenAI | AI models via API for AI-assisted content generation | United States · GDPR safeguards |
| Google Gemini | AI models via API for AI-assisted content generation | United States · GDPR safeguards |
All providers apply security and data protection measures aligned with their respective regulatory obligations. The detail of sub-processors and the specific processing conditions are governed by the Data Processing Agreement (DPA) included in the services contract.
Any change to sub-processors will be notified to clients in advance.
10.1 Security of the AI integration
- All calls to AI models are executed from the backend. They are never made directly from the user's browser.
- API credentials are never exposed to the end user.
- Prompts are structured and controlled by backend logic.
- Prompts do not include personal identifiers: names and email addresses are excluded, and contextual information is anonymised.
- Neither prompts nor outputs are used to retrain models.
Full detail is available on our AI Usage and Transparency page.
11. Data retention and deletion
Personal data is retained only for as long as necessary to deliver the contracted service.
| Category | Retention |
| User account data | Duration of the service relationship |
| Profile analysis data | Duration of the analytics programme |
| AI-generated content | Only where the user chooses to save it. Editable or deletable at any time. |
On termination of the contractual relationship, data will be deleted or returned to the client, unless a legal retention obligation applies.
12. Legal bases and processing roles
12.1 Legal bases
- Performance of the contract: for the delivery of Scoringmy services.
- Consent of the data subject: where employees agree to take part in the programme.
- Legitimate interest: for the analysis of professional information published on open sources for professional benchmarking purposes.
12.2 Roles
| PeopleXBrand's role | Context |
| Data Controller | Where the user creates their individual account, or the employee agrees to take part in the programme. |
| Data Processor | Where employee data is processed on behalf of a client company. |
13. Data subject rights
Data subjects may exercise their rights of access, rectification, erasure, restriction of processing, objection and portability at any time by writing to legal@scoringmy.com.
14. Regulatory compliance
Scoringmy has been designed with the following in mind:
- General Data Protection Regulation (GDPR)
- Privacy by Design principles
- Data minimisation principles
- EU AI Act governance principles: human oversight, transparency and responsible use
The platform processes only the professional information required to deliver the service, and integrates third-party AI models without developing or training them.
15. Continuous improvement
Scoringmy continuously reviews and improves its security processes to strengthen the reliability and protection of the platform as it evolves.
16. Security policies
Set out below is the full text of Scoringmy's internal security policies. These are the same policies provided to compliance teams during supplier onboarding and approval processes.
16.1 Access Control Policy
Purpose
This policy defines how access to the platform and to data is controlled.
Access model
Role-Based Access Control (RBAC). The roles defined are:
- Admin: full access.
- Employee: restricted access.
Authorisation
- Permissions are managed centrally.
- They are enforced consistently across all modules.
Authentication
- Access is restricted to authenticated users.
- Administrative access is limited to authorised personnel.
User lifecycle
- Access is granted on the basis of business need.
- Access can be modified or revoked at any time.
Principle of least privilege
Users access only the data and features necessary for their role.
16.2 Backup and Recovery Policy
Purpose
This policy defines the backup and recovery procedures implemented by Scoringmy to ensure data availability and integrity, and business continuity in the event of system failure or data loss.
Scope
- Production environment
- Application data
- System configurations and infrastructure
Backup strategy
Scoringmy implements automated backup processes to ensure that data is regularly preserved and recoverable.
- Full backups are performed daily.
- Backup processes are automated and scheduled.
Storage and security
- Backups are stored securely within the hosting infrastructure (Hetzner).
- Access to backup systems is restricted to authorised personnel only.
- Backup data is protected using infrastructure-level security controls.
- Production systems are not directly exposed to public access.
- Backups are stored separately from production systems.
Retention policy
- Backup snapshots are retained on a rolling basis.
- Multiple recovery points are maintained to provide flexibility in restoration.
- Historical backups allow recovery from recent system states.
Recovery capability
Scoringmy backups allow the system to be restored in the event of:
- System failure
- Data corruption
- Operational incidents
- Accidental data loss
Recovery procedures enable restoration of the application environment and associated data.
Access control
- Backup access is limited to authorised technical personnel only.
- Access is managed through secure authentication mechanisms.
- Permissions follow internal access control policies.
Monitoring and validation
- Backup processes are monitored to ensure successful execution.
- System logs allow backup activity to be verified.
- Any issues detected are reviewed and addressed accordingly.
Continuous improvement
Scoringmy continuously reviews and improves its backup processes to enhance reliability and security as the platform evolves.
16.3 Security Testing and Vulnerability Management Policy
Purpose
This policy defines how Scoringmy identifies, mitigates and manages security vulnerabilities.
Security approach
Security is implemented using a layered model:
- Cloudflare protection: web application firewall (WAF), DDoS mitigation and traffic filtering.
- Secure backend architecture: reverse-proxy model, with no direct exposure of the origin infrastructure.
- Access control: role-based model, with restricted access to production systems.
- Infrastructure-level protection.
Vulnerability management
- Application dependencies are regularly updated.
- Security configurations are reviewed periodically.
- Issues are addressed as part of ongoing maintenance.
Monitoring and detection
- Real-time logging and monitoring.
- Tracking of system activity, transactions and anomalies.
- Logs are available for investigation and analysis.
External auditing
Security is currently maintained through continuous internal controls and ongoing monitoring. The introduction of formal third-party security testing (penetration testing) is part of the platform's roadmap, as an element of the continuous improvement programme.
Continuous improvement
Security practices are continuously reviewed and improved over time.
17. Security FAQs
Direct answers to the questions most commonly raised in supplier security questionnaires.
Where is the data hosted?
At Hetzner Online GmbH (Germany, European Union). The core infrastructure carries out no international transfers outside the European Economic Area.
Are communications encrypted?
Yes. HTTPS with TLS 1.2/1.3 across all communications, enforced at the Cloudflare layer, including API calls to external services.
Do you process special categories of personal data?
No. Scoringmy processes professional data only. We do not process health data, ethnic origin, beliefs, sexual orientation or biometric data.
Is personal data sent to the AI models?
No. Prompts exclude names, email addresses and personal identifiers. Contextual information is anonymised before it is sent. Neither prompts nor outputs are used to retrain models.
How often are backups taken?
Full daily backups, automated, stored separately from production and with multiple recovery points.
How quickly do you notify a security breach?
Without undue delay and within a maximum of 24 hours of detection.
Do you carry out external penetration testing?
Security is currently maintained through continuous internal controls, a perimeter web application firewall and ongoing monitoring. External auditing is part of the platform's roadmap.
Does Scoringmy scrape LinkedIn?
No. Scoringmy does not scrape and does not automate user behaviour. It is offered as a third-party application and is not endorsed or backed by LinkedIn.
Is there an availability SLA?
The platform is designed for high availability and service continuity. Specific service level commitments are agreed contractually.
Can you sign a DPA?
Yes. The Data Processing Agreement is included in the services contract and governs sub-processors and the specific conditions of processing.
Need to complete a security questionnaire?
If your security, legal or compliance teams need additional documentation, or need a supplier assessment questionnaire completed, write to us at legal@scoringmy.com. We are happy to expand on any point that requires further detail.
Contact
- Security and privacy: legal@scoringmy.com
- Legal entity: PeopleXBrand Aceleradora S.L.
- Company number (CIF): B-56994916
- Address: C/ Gregorio Benítez 10, 28043 Madrid (Spain)