Security
What we do to protect your records, and what we have not done yet.
You are putting your certificates, audits and corrective actions here, and several of those records name individual people. This page says what happens to them.
Who we are
Easy Audit is operated by Golden Phi, established in Egypt. We are a small team, and this page is written to be checked rather than to reassure.
Keeping your data apart from everyone else's
Every record belongs to one company and every request is scoped to the company making it. A user of one organization cannot reach another's data by any route, including by putting somebody else's record number in an address. This is not a matter of hiding links: the check runs on our servers for every request, and dedicated automated tests exist to prove that typing an address by hand gets the same refusal as clicking a button that was not shown.
Who can see what
Permissions are held per role and checked server-side on every request. Your organization decides who is invited, what role they hold, and what an outside auditor may reach — an auditor sees your data only through a grant you issued, with a scope you set, and you can withdraw it.
Deactivating somebody signs them out everywhere immediately rather than at the end of their session.
Signing in
- Passwords are stored as scrypt hashes and never in a form anybody can reverse. We never send a password by email.
- Two-factor authentication is available to every user, with single-use recovery codes for when a phone is lost. Your plan can require it for everybody in your organization.
- Everyone who administers the platform itself is required to use two-factor — not offered it.
- Sign-in locks after repeated failures, and every failed attempt takes the same amount of time, so the response cannot be used to discover which accounts exist.
- Sessions expire after twelve idle hours.
Your files
Uploads are limited to known file types and checked against their actual content, so a file cannot arrive pretending to be something else. Stored names are generated by us and never taken from the uploaded filename. Files live in a private bucket and are served through links that expire — there is no public address for any file you upload.
Encryption
Every connection uses HTTPS. The database and the file storage are encrypted at rest by their providers. Two-factor secrets are encrypted with a key held separately.
What we record
Eighty-five kinds of event are written to an audit log: sign-ins and failed sign-ins, password and two-factor changes, role changes, file uploads, downloads and deletions, approvals, backups and restores. Your administrators can read your own company's log.
It is not an append-only log. A company administrator can purge entries older than ninety days, and we can purge anything. The ninety-day floor exists so that the people the log holds accountable cannot erase the recent past. We would rather tell you that than let you assume otherwise.
Backups
The database is copied nightly and kept for fourteen days, with a copy sent to separate storage. Your organization also gets its own archives on a schedule you set, and can restore them itself.
Deleting a record removes it from the live system that day. Copies taken while it existed hold it until they are replaced — up to fourteen days for the database backup. We do not edit old backups to cut records out of them, because a backup that has been edited cannot be trusted to restore.
Where your data is
Application servers and files are in Europe (Stockholm). The database is in Europe (London). Outgoing email passes through Namecheap Private Email. Payments are handled by Paddle as merchant of record.
We never store card or bank details. Nothing that could be used to charge a card exists in our database, and no feature may be built that would put one there.
The full list of who touches your data, with what and where, is in our privacy policy.
How we build it
Around three thousand automated tests run on every change, before it can reach production. Security behaviour is tested as behaviour — tenant separation, permission boundaries and sign-in each have their own tests that fail loudly. Dependencies are scanned and updated weekly, and the repository is scanned for secrets.
If something goes wrong
We have a written incident response procedure. If a breach affects your data we tell you within 24 hours of becoming aware, before we have the full picture rather than after, because your own obligations cannot start until we tell you. Where the law requires us to notify the regulator, we do.
Your rights
Anyone can ask us about their own data at our request page — no account needed. We confirm the address first, answer within 30 days, and keep a record of what we did. If the data belongs to a customer's workspace we pass the request to them, because it is theirs to decide.
What we have not done
A page that lists only strengths tells you nothing about how carefully the rest of it was written. These are the gaps, and we would rather you read them here than find them:
- We hold no ISO 27001 or SOC 2 certification, and this page should not be read as claiming one.
- We have not had an external penetration test.
- We have no uptime monitoring or intrusion detection. We find out about an outage from our own daily checks or from you.
- We have not yet rehearsed a full database restore, so we do not quote a recovery time — we would rather say nothing than quote a number nobody has measured.
- There is no second person with production access today. That is a real risk of a business this size and we do not pretend otherwise.
- We are working through Egypt's data protection licensing with counsel and do not yet hold the licences it requires.
If any of these matters to your decision, ask us. We will tell you where it actually stands rather than when we hope it will change.
Last reviewed 27 August 2026. If you find something on this page that is not true, tell us and we will correct it the same day.