Skip to content
Home
Security & Compliance

Serious safeguards for your data

Your agency's client, project, and inventory data is sensitive. When we designed TodoMore, we treated security as a principle built into the foundation — not a layer bolted on afterward. We share the controls we run and our roadmap transparently here.

Core Controls

Encryption in transit & at rest

All traffic is encrypted in transit with TLS 1.3. Data is encrypted at rest (AES-256) on the underlying database and storage infrastructure.

Row Level Security

With Supabase PostgreSQL RLS policies, every query is limited to the rows the session is authorized for. This cuts cross-tenant leakage risk at the architecture level.

Hosting in the EU Region

All data is stored in the Frankfurt (Supabase eu-central-1) region. No transfers are made outside the EU.

Daily Backups + Point-in-time Recovery

Full daily backups plus any-second restore for the last 7 days. For disaster scenarios we target RPO < 1 hour and RTO < 4 hours.

2FA & Session Security

TOTP-based two-factor authentication is available for all users. Session tokens are rotated, with re-authentication required for sensitive operations.

Role-Based Access

With Owner / Admin / Moderator / Member / External roles, each module can be restricted individually. Every permission change is tracked in the audit log.

Compliance & Processes

KVKK & GDPR Compliance

We maintain a personal data inventory, keep processing purposes transparent, and implement disclosure notices and explicit consent flows within the product.

  • Right to erasure (Account Settings → Delete My Account)
  • Right to data portability (CSV / JSON export)
  • Right of access (within 30 days via a support request)
  • DPA (Data Processing Agreement) for B2B

Vulnerability Disclosure

We operate a responsible disclosure policy. If you believe you have found a security vulnerability, please report it to us; our response time is within the first 48 hours.

  • info@letstodomore.com
  • PGP key on request
  • Security acknowledgments — for verified researchers

Incident Response

We have a defined Incident Response Playbook. For incidents affecting personal data, we notify the affected individuals within 72 hours and fulfill our obligation to report to the KVKK Authority.

Certifications & Roadmap

Public Status Page

status.letstodomore.com

Planned

SOC 2 Type I

Target Q4 2026

On the Roadmap

ISO/IEC 27001

alongside market demand

Under Review

Independent penetration test

A third-party test is planned; the summary will be shared on this page.

Planned

This page is reviewed and updated regularly.

Spotted a Security Issue?

Report it to us under our responsible disclosure policy. We respond within 48 hours; for valid findings you'll be added to our thank-you list.

info@letstodomore.com