Trust center

Security, privacy and compliance

How Maketools protects your organisation's data and your players' data: where it is hosted, how it is encrypted, which controls are in place and who processes it.

Data hosted in the European Union

All platform data stays in the EU, in a single AWS region.

  • Application, databases and file storage run on Amazon Web Services in the Paris region (eu-west-3), on infrastructure that Maketools operates itself and describes as code.
  • Only the content delivery network faces the Internet, behind a web application firewall in production: the application servers are reachable only through it, and the databases and cache live in isolated subnets with no Internet access.
  • The website is served from Amazon S3 through the Amazon CloudFront content delivery network, over HTTPS only.
  • Staging and production are separate environments, with their own secrets. Production data is never copied to staging.

Encryption

Data is encrypted in transit and at rest; credentials are never stored in a readable form.

  • In transit: TLS on every connection, down to the databases and the cache, with HTTP Strict Transport Security (HSTS, preload).
  • At rest: databases (Amazon RDS) and their backups, cache (Amazon ElastiCache), message queues and file storage (Amazon S3) are encrypted.
  • Passwords are hashed with scrypt and re-hashed automatically when the cost parameters increase.
  • Session tokens, one-time codes and API keys are stored only as SHA-256 hashes.
  • Two-step verification secrets, SSO client secrets and LRS credentials are encrypted with AES-256-GCM, bound to their account or organisation, under rotatable keys.

Security controls

Technical controls in place today, mapped to ISO/IEC 27001:2022 Annex A and to the SOC 2 Trust Services Criteria.

Aligned, not certified

These controls are designed and tested against ISO 27001 and SOC 2. Maketools does not hold an ISO 27001 certification or a SOC 2 report at this stage. Our hosting provider (AWS) holds its own certifications and attestations.

  • Immutable audit log

    • Sign-ins, member and role changes, security policy, game releases and deployments, exports and data erasure are recorded.
    • Append-only log: entries can be neither modified nor deleted before the end of their retention period.
    • Entries are chained with SHA-256 hashes; the chain is verified every day, including after each purge, which keeps an anchor of the last purged entry.
    • Readable by organisation owners and admins, and kept for 12 months: as recommended for access logs by the French data protection authority (CNIL), and long enough for a SOC 2 Type II observation period.

    References:ISO 27001 5.28, 5.33, 8.15SOC 2 CC4.1, CC7.2

  • Strong authentication

    • Two-step verification (TOTP and single-use backup codes) is required to manage the security of an organisation and to expose player data. Each organisation can require it from its privileged roles or from all its members, with a 7-day delay announced to each of them.
    • Sessions in secure, HttpOnly cookies, with a 24-hour inactivity timeout for privileged roles.
    • Sensitive actions (email, password, two-step verification settings, account deletion) require recent re-authentication.
    • Rate limiting and progressive lockout per account and per network address; error messages never reveal whether an account exists.
    • Google and Microsoft sign-in handled server-side, with PKCE and nonce.

    References:ISO 27001 5.17, 8.5SOC 2 CC6.1, CC6.6

  • Access control and isolation

    • Deny by default: every endpoint checks a permission against a single role matrix (owner, admin, editor, analyst, member).
    • Every organisation's data is isolated; cross-organisation access is tested for each service.
    • Nobody can grant a role higher than their own, and every organisation always keeps an owner.
    • Platform administrators must use two-step verification and every one of their actions is audited.
    • Maketools staff act only as named operators, each with a personal, time-limited key that never leaves their machine; every lookup and every action is logged. A key reserved for statistics only reads aggregates and cannot change anything.
    • Catalogue curation is a separate internal role that gives no access to customer data, and our team only works inside an organisation (for example to customise a game) when that organisation invites it, which shows in its audit log.

    References:ISO 27001 5.15, 5.18, 8.2, 8.3SOC 2 CC6.1, CC6.3, C1.1

  • Application security

    • Strict Content Security Policy (no inline scripts, Trusted Types), HSTS, anti-framing and hardened security headers.
    • Cross-site request forgery protection on every state-changing request.
    • The API is only reachable through our CDN: direct calls to the application servers are refused.
    • Controlled uploads: images only, type checked on content, 2 MB maximum, re-encoded server-side with metadata removed.
    • Scores are computed by the server; spreadsheet exports are protected against formula injection.
    • Rate limits on costly or abusable actions (invitations, exports, uploads, sign-ups, payments, reports), counted per network address and per account.
    • Any player can report a published game; the moderation team can suspend it, and the organisation receives the reason and the way to contest the decision.
    • Personal data and secrets are masked in application logs and kept out of request traces.
    • An adversarial security review is run before production releases; every confirmed finding is fixed with a regression test.

    References:ISO 27001 8.7, 8.11, 8.23, 8.26SOC 2 CC6.6, CC6.8, CC8.1

  • Secure development

    • Static analysis (SAST) on every change, including OWASP Top 10 rules.
    • Dependency audit blocking high and critical vulnerabilities, weekly even without changes, with automated update proposals.
    • Secret scanning across the whole code history; secrets are managed per environment in a dedicated vault (AWS Secrets Manager), outside the code and the deployed images.
    • Mandatory automated tests and coverage thresholds before any merge.

    References:ISO 27001 8.4, 8.8, 8.25, 8.29SOC 2 CC7.1, CC8.1

  • Backups

    • Automatic database backups with point-in-time recovery, in the EU region; in production, the database is protected against deletion and can be restored in another availability zone.

    References:ISO 27001 8.13SOC 2 A1.2

GDPR and privacy

Players' data belongs to the organisation that invites them. We collect only what the games and reports need.

Read the full privacy policy

Who is responsible

Your organisation is the data controller for its players' data (game sessions, scores, reports). Maketools acts as its processor and follows its instructions.

Maketools is the data controller for user accounts, billing and its aggregated, anonymous internal usage statistics.

Data subject rights

  • Access and portability: every user exports their data as JSON, self-service, from their account.
  • Erasure: account deletion is self-service and takes effect across all services within 30 days.
  • Rectification: name and email address can be edited at any time from the account.

Privacy in reports

  • Reports are pseudonymised by default: players appear as Player-XXXX, a pseudonym that differs from one organisation to another.
  • Named reports are an explicit decision of the organisation, which informs its players.
  • A report filtered on a group of fewer than 5 players is never detailed, neither on screen nor in exports.

Retention

Retention periods
DataRetention
User account Until deletion by the user
Raw game events 13 months, then anonymous aggregates only
Expired tokens and one-time codes Deleted 7 days after expiry
Audit log 12 months, then purged
Generated report exports 24 hours
Internal usage statistics (aggregates, no personal data) No time limit; the identifier of a deleted organisation is replaced by a random identifier
Pseudonymised activity days (active user count) 35 days, then deleted
Custom game requests (email to the sales team, nothing is stored by the platform) 3 years after the last contact, then deleted
Technical application logs (errors and service monitoring) 30 days, then deleted

No third-party trackers: no advertising or analytics cookies. Network addresses are kept only in the audit log.

Subprocessors

Third parties that process personal data on our behalf.

List of subprocessors
SubprocessorPurposeData location
Amazon Web Services EMEA SARL Hosting of the application, databases, files and website European Union (Paris, eu-west-3)
Resend Transactional emails (sign-in codes, invitations, notifications) United States
Stripe Payment, billing and VAT calculation (Stripe Tax); card details never transit through Maketools Ireland and United States

Security contact

Found a vulnerability, or have a security or privacy question? Write to us.

Security team:charlotte@maketools.ai

Responsible disclosure

We welcome reports from security researchers. Please report privately, do not access or modify data that is not yours, and give us reasonable time to fix the issue before any public disclosure.

Machine-readable contact: security.txt