Skip to content
Tigh Sauna

Security

Your customers’ data, handled properly.

A sauna holds names, phone numbers, visit history and occasionally a health note. That is personal data under GDPR. This page sets out the controls that protect it.

EU hosting

  • Application and database hosted within the European Union.
  • No routine transfer of personal data outside the EEA.
  • Sub-processors named publicly, with their locations.

Separation between customers

  • Every record carries the organisation that owns it.
  • Isolation enforced by row level security in the database, not only in application code.
  • The runtime role cannot bypass those policies.

Encryption

  • TLS on every connection, HTTPS only, HSTS enabled.
  • Data encrypted at rest by the hosting platform.
  • Card details never touch our servers.

Access

  • Staff accounts scoped by role. Owners see billing and reporting, staff do not.
  • Our own access to customer environments is limited to support and is logged.
  • Credentials held in a managed secret store, never in the codebase.

Resilience

  • Automated backups with point in time recovery.
  • Recovery point objective under one hour.
  • Recovery time objective of one hour.

Change control

  • Automated tests run on every change before it can ship.
  • Booking and payment paths carry the heaviest test coverage.
  • Changes are deployed from version control, never by hand on a server.

Current position

What we do not yet claim.

Our position on certification, testing and availability, stated plainly.

  • We do not currently hold ISO 27001 or a SOC 2 report. If certification is a procurement requirement for you, tell us early and we will set out exactly where we stand.
  • No independent penetration test has been published. When one is completed it will be listed here with its date.
  • Tigh Sauna is a cloud product, so the console at your counter needs a working connection. Bookings taken online are unaffected by an outage at your premises.

Disclosure

Reporting a vulnerability.

Email security@tighsauna.com with what you found and how to reproduce it. We acknowledge within two working days and we will not pursue action against anyone acting in good faith.

Out of scope

Please do not run automated scanners against production, access or alter data that is not yours, or disclose an issue publicly before we have had a reasonable opportunity to fix it.

Related: data processing agreement, sub-processors and service levels.

See it running against your own schedule.

Thirty minutes, screen shared, with your prices and sessions loaded in. If it is not the right fit, we will tell you.