Get 10% off your first eSIM!

Centar za Povjerenje

Security, privacy and compliance information about AetopOne. Learn about our data protection, security measures, and compliance standards.

Core Security Features

Security

  • End-to-end encryption for all data transmission
  • Secure authentication with NextAuth.js
  • Regular security audits and penetration testing
  • Multi-factor authentication support
  • Secure API endpoints with rate limiting

Privacy

  • GDPR compliant data handling
  • User consent management system
  • Data minimization principles
  • Right to data deletion
  • Transparent data processing

Compliance

  • GDPR compliance standards
  • PCI DSS compliance for payments
  • Regular compliance audits
  • Data protection impact assessments
  • Incident response procedures

Third-Party Services & Infrastructure

We use industry-leading third-party services to ensure the highest standards of security, reliability, and performance. All services are carefully selected and regularly audited for security compliance.

Infrastructure & Hosting

DigitalOcean

Cloud Infrastructure & Container Registry

Our applications are hosted on DigitalOcean's secure cloud infrastructure with enterprise-grade security, automated backups, and 99.99% uptime SLA.

Data Location: Germany • Security: SOC 2 Type II, ISO 27001

Docker & Caddy

Containerization & Reverse Proxy

Containerized deployment with Docker for consistent environments and Caddy as a secure reverse proxy with automatic SSL certificate management.

Security: Automated SSL, HTTP/2, Security Headers

Business & Analytics Services

Stripe

Payment Processing & Tax Calculation

Secure payment processing with PCI DSS Level 1 compliance, fraud detection, and automated tax calculation for international transactions.

Compliance: PCI DSS Level 1 • Security: SOC 1, SOC 2, ISO 27001

Brevo (formerly Sendinblue)

Email Marketing & Communication

GDPR-compliant email marketing platform for transactional emails, marketing communications, and customer support with advanced deliverability features.

Compliance: GDPR, CAN-SPAM • Security: ISO 27001, SOC 2

Brevo Chat Widget

Live Chat Support & Customer Service

Real-time customer support chat widget integrated with our support ticketing system for immediate assistance and seamless customer experience.

Compliance: GDPR compliant • Security: Encrypted chat sessions

OpenAI

AI-Powered Support Chat (Mobile)

Intelligent AI chatbot for mobile app support using OpenAI's advanced language models to provide instant, helpful responses to customer inquiries and support requests.

Privacy: GDPR compliant • Data: Minimal conversation logs

Monitoring & Analytics

Sentry

Error Monitoring & Performance Tracking

Real-time error monitoring and performance tracking to ensure application reliability and quick issue resolution with privacy-focused data collection.

Privacy: GDPR compliant • Data: Error logs only

PostHog

Product Analytics & User Behavior

Privacy-focused product analytics for understanding user behavior and improving product experience with GDPR compliance and data anonymization.

Privacy: GDPR compliant • Data: Anonymized usage patterns

eSIM & Connectivity Services

Airalo

eSIM Provider & Global Connectivity

Global eSIM connectivity provider with secure activation, real-time usage tracking, and comprehensive coverage across 200+ countries and regions.

Coverage: 200+ countries • Security: Encrypted activation

Development & CI/CD

GitHub

Version Control & CI/CD

Secure source code management with automated testing, security scanning, and deployment workflows to DigitalOcean infrastructure.

Security: Advanced security scanning • Features: Dependabot alerts

Slack

Team Communication & Notifications

Secure team communication platform for deployment notifications, incident alerts, and team collaboration with enterprise-grade security.

Security: Enterprise security • Compliance: SOC 2, ISO 27001

Data Protection & Privacy

Our Commitment to Data Protection

Data Minimization

We only collect and process data that is necessary for providing our services and improving user experience.

User Consent

All data processing is based on explicit user consent, which can be withdrawn at any time.

Data Encryption

All data is encrypted in transit and at rest using industry-standard encryption protocols.

Right to Deletion

Users have the right to request deletion of their personal data in accordance with GDPR requirements.

Questions About Security?

If you have any questions about our security practices, data protection measures, or compliance standards, please don't hesitate to contact us.

security@aetopone.com

Secure payment processing with all major credit cards, digital wallets, and local payment methods.