Security and trust
How we protect data
This page explains Takto's current data boundary, the providers used by the public site and pilot intake, and the controls that must be in place before we process production customer ERP data.
What is in place today
- The public website is hosted on Google Firebase Hosting and served over HTTPS.
- Current pilot intake operations use restricted Google Workspace records. Access is limited to named team members.
- Cloudflare Turnstile is used where a public form needs bot protection.
- Slack may receive a limited internal notification about an intake submission. Full submitted answers remain in the restricted Google record.
- Takto does not write changes back to a customer's ERP or reprice anything automatically.
Customer data remains the customer's
The customer owns the ERP data and documents it provides. Takto may process that data only to provide the agreed service and under the customer's instructions. We do not sell Customer Data. The terms of service and data processing agreement set out that boundary.
Facts, estimates, and human decisions
Takto separates source data from interpretation. A finding includes its source, confidence, and supporting evidence where available. External signals are shown separately from information read from the customer's systems. Takto flags possible issues and next steps, but an authorised person decides whether to act. The service does not provide legal, financial, tax, or audit advice.
Current public-site and pilot providers
The providers below support the public website and current pilot intake. This is not a final list of subprocessors for production customer ERP data. That list will be confirmed before such processing begins.
| Provider | Current purpose | Transfer position |
|---|---|---|
| Firebase Hosting for takto.se; Google Workspace, Sheets, and Apps Script for current intake operations. | Provider terms and applicable safeguards govern any processing outside the EU/EEA. | |
| Cloudflare | Turnstile bot protection on forms that use it. | Cloudflare operates a global network. Provider terms and applicable safeguards govern international transfers. |
| Slack | Optional, limited internal intake notifications. Full onboarding answers are not sent in the notification. | Provider terms and applicable safeguards govern any processing outside the EU/EEA. |
Before we process production customer ERP data
The following decisions and controls must be documented for the actual production setup before customer ERP data is processed:
- The hosting provider, database, processing region, and applicable international transfer mechanism.
- The production identity provider, individual accounts, multi-factor authentication, access roles, and joiner, mover, and leaver process.
- Strict separation between customers and a reviewed support-access process.
- Encryption in transit and at rest, secrets management, backup and restore, monitoring, patching, logging, and incident response.
- A complete subprocessor list and a customer-ready data processing agreement that matches the deployed infrastructure.
- A security review and testing plan appropriate to the launch scope.
Takto does not currently claim ISO 27001 or SOC 2 certification, or that an independent penetration test has been completed. We will update this page when the production design and evidence exist.
Data protection
Rinda Venture Studio AB (organisation number 559596-8800) operates Takto. When we process personal data in Customer Data under a customer's instructions, the customer is the controller and we are the processor. Our data processing agreement covers that processing. The privacy notice explains how we handle personal data for which we are the controller.
Report a security concern
Send a security question or vulnerability report to hello@takto.se. Please do not include passwords, production data, or other sensitive material in the first message. We will arrange a safer way to share details if needed.