Tento dokument je momentálně dostupný pouze v anglickém originále. Přepněte prosím jazyk pomocí tlačítka vpravo nahoře, nebo si přečtěte anglickou verzi níže.
Strimeta Security Overview and Technical & Organisational Measures
Product: Strimeta
Operator / Provider: Jakub Marcinka, trading under jmarcinka.cz
IČO: 21474672
Business address: Na Kopci 1210/10, 460 14 Liberec XIV-Ruprechtice, Czech Republic
Contact: jmarcinka@email.cz
Website: https://jmarcinka.cz
Version: 1.0
Effective date: 9 September 2026
Status. This is Strimeta's operational legal documentation prepared for launch. Mandatory law prevails over contractual text. Because international privacy, tax, consumer and platform rules change, the regional launch gates and vendor list must be re-checked before entering a new market or materially changing the product.
1. Security objective
Strimeta uses defence in depth to reduce the likelihood and impact of unauthorised access, data loss, service compromise and cross-customer exposure. Controls are reviewed when architecture or risk materially changes.
2. Identity and access
- unique privileged identities; no routine shared admin credentials;
- MFA for privileged/owner access where supported;
- least privilege and role separation;
- access removal after role change or departure;
- audit logging of sensitive administrative actions;
- separate service credentials and secret rotation.
3. Application and API security
- authenticated APIs and authorisation checks scoped to customer/community;
- input validation and safe parsing;
- request/rate limits and abuse controls;
- CSRF protection where browser sessions require it;
- secure session cookies and TLS;
- dependency and vulnerability review;
- security-relevant error taxonomy and monitoring without leaking secrets.
4. Data minimisation
Strimeta stores the minimum connector metadata required for defined analytics. Discord message content is not persistently stored by default. Logs must not contain passwords, API tokens, full secrets or unnecessary message content.
5. Infrastructure
Production runs on Contabo under the Strimeta production profile. The legal baseline assumes an EU/EEA data-centre location. Host access is restricted; routine operations should be performed through controlled deployment/administration workflows rather than broad SSH access.
6. Backups
Backups are encrypted before leaving the production boundary. Recovery copies are kept at: (a) Contabo, (b) the Provider's encrypted workstation and (c) the Provider's encrypted NAS. Backup keys are kept separately from backup archives. Restore tests are performed periodically. Backup copies containing Customer/community personal data follow the 90-day maximum operational backup-retention rule unless a narrower configured period applies.
7. Logging and monitoring
Security logs record enough information to investigate authentication, privilege changes, connector failures, unusual data access, configuration changes and operational incidents. Logs are access-restricted, tamper-resistant where practicable and retained only for a defined period.
8. Incident response
Strimeta maintains an incident process for triage, containment, evidence preservation, eradication, recovery, breach assessment, customer notification and regulatory escalation. The internal target is to escalate suspected personal-data breaches immediately so the shortest applicable statutory deadline can be met.
9. Vendor security
Before a vendor receives Customer Personal Data, Strimeta documents purpose, role, data categories, location, security commitments, DPA/contractual protection and transfer mechanism. Material vendor changes trigger review and customer notice where required.
10. Development and change control
Changes should pass code review/testing appropriate to risk, automated checks where available and controlled deployment. Secrets are never committed to source control. Production data is not copied into test environments without a documented, minimised and protected exception.
11. Business continuity
Strimeta maintains deployment/rollback capability, health/readiness checks and restore procedures. Recovery procedures are tested rather than relying solely on successful backup-job status.
12. Customer responsibilities
Customers must secure their administrator accounts, limit integration permissions to those necessary, remove stale access, lawfully configure retention and notify Strimeta promptly of suspected compromise.
Strimeta Security Overview and Technical & Organisational Measures
Product: Strimeta
Operator / Provider: Jakub Marcinka, trading under jmarcinka.cz
IČO: 21474672
Business address: Na Kopci 1210/10, 460 14 Liberec XIV-Ruprechtice, Czech Republic
Contact: jmarcinka@email.cz
Website: https://jmarcinka.cz
Version: 1.0
Effective date: 9 September 2026
Status. This is Strimeta's operational legal documentation prepared for launch. Mandatory law prevails over contractual text. Because international privacy, tax, consumer and platform rules change, the regional launch gates and vendor list must be re-checked before entering a new market or materially changing the product.
1. Security objective
Strimeta uses defence in depth to reduce the likelihood and impact of unauthorised access, data loss, service compromise and cross-customer exposure. Controls are reviewed when architecture or risk materially changes.
2. Identity and access
- unique privileged identities; no routine shared admin credentials;
- MFA for privileged/owner access where supported;
- least privilege and role separation;
- access removal after role change or departure;
- audit logging of sensitive administrative actions;
- separate service credentials and secret rotation.
3. Application and API security
- authenticated APIs and authorisation checks scoped to customer/community;
- input validation and safe parsing;
- request/rate limits and abuse controls;
- CSRF protection where browser sessions require it;
- secure session cookies and TLS;
- dependency and vulnerability review;
- security-relevant error taxonomy and monitoring without leaking secrets.
4. Data minimisation
Strimeta stores the minimum connector metadata required for defined analytics. Discord message content is not persistently stored by default. Logs must not contain passwords, API tokens, full secrets or unnecessary message content.
5. Infrastructure
Production runs on Contabo under the Strimeta production profile. The legal baseline assumes an EU/EEA data-centre location. Host access is restricted; routine operations should be performed through controlled deployment/administration workflows rather than broad SSH access.
6. Backups
Backups are encrypted before leaving the production boundary. Recovery copies are kept at: (a) Contabo, (b) the Provider's encrypted workstation and (c) the Provider's encrypted NAS. Backup keys are kept separately from backup archives. Restore tests are performed periodically. Backup copies containing Customer/community personal data follow the 90-day maximum operational backup-retention rule unless a narrower configured period applies.
7. Logging and monitoring
Security logs record enough information to investigate authentication, privilege changes, connector failures, unusual data access, configuration changes and operational incidents. Logs are access-restricted, tamper-resistant where practicable and retained only for a defined period.
8. Incident response
Strimeta maintains an incident process for triage, containment, evidence preservation, eradication, recovery, breach assessment, customer notification and regulatory escalation. The internal target is to escalate suspected personal-data breaches immediately so the shortest applicable statutory deadline can be met.
9. Vendor security
Before a vendor receives Customer Personal Data, Strimeta documents purpose, role, data categories, location, security commitments, DPA/contractual protection and transfer mechanism. Material vendor changes trigger review and customer notice where required.
10. Development and change control
Changes should pass code review/testing appropriate to risk, automated checks where available and controlled deployment. Secrets are never committed to source control. Production data is not copied into test environments without a documented, minimised and protected exception.
11. Business continuity
Strimeta maintains deployment/rollback capability, health/readiness checks and restore procedures. Recovery procedures are tested rather than relying solely on successful backup-job status.
12. Customer responsibilities
Customers must secure their administrator accounts, limit integration permissions to those necessary, remove stale access, lawfully configure retention and notify Strimeta promptly of suspected compromise.