Serious safeguards for your data
Your agency's client, project, and inventory data is sensitive. When we designed TodoMore, we treated security as a principle built into the foundation — not a layer bolted on afterward. We share the controls we run and our roadmap transparently here.
Core Controls
Encryption in transit & at rest
All traffic is encrypted in transit with TLS 1.3. Data is encrypted at rest (AES-256) on the underlying database and storage infrastructure.
Row Level Security
With Supabase PostgreSQL RLS policies, every query is limited to the rows the session is authorized for. This cuts cross-tenant leakage risk at the architecture level.
Hosting in the EU Region
All data is stored in the Frankfurt (Supabase eu-central-1) region. No transfers are made outside the EU.
Daily Backups + Point-in-time Recovery
Full daily backups plus any-second restore for the last 7 days. For disaster scenarios we target RPO < 1 hour and RTO < 4 hours.
2FA & Session Security
TOTP-based two-factor authentication is available for all users. Session tokens are rotated, with re-authentication required for sensitive operations.
Role-Based Access
With Owner / Admin / Moderator / Member / External roles, each module can be restricted individually. Every permission change is tracked in the audit log.
Compliance & Processes
KVKK & GDPR Compliance
We maintain a personal data inventory, keep processing purposes transparent, and implement disclosure notices and explicit consent flows within the product.
- Right to erasure (Account Settings → Delete My Account)
- Right to data portability (CSV / JSON export)
- Right of access (within 30 days via a support request)
- DPA (Data Processing Agreement) for B2B
Vulnerability Disclosure
We operate a responsible disclosure policy. If you believe you have found a security vulnerability, please report it to us; our response time is within the first 48 hours.
- info@letstodomore.com
- PGP key on request
- Security acknowledgments — for verified researchers
Incident Response
We have a defined Incident Response Playbook. For incidents affecting personal data, we notify the affected individuals within 72 hours and fulfill our obligation to report to the KVKK Authority.
Certifications & Roadmap
Public Status Page
status.letstodomore.com
SOC 2 Type I
Target Q4 2026
ISO/IEC 27001
alongside market demand
Independent penetration test
A third-party test is planned; the summary will be shared on this page.
This page is reviewed and updated regularly.
Spotted a Security Issue?
Report it to us under our responsible disclosure policy. We respond within 48 hours; for valid findings you'll be added to our thank-you list.
info@letstodomore.com