TUNDRÄ
Services
Web development Frontend, backend and integrations Development retainer Compare monthly support models Website maintenance Ongoing fixes, updates and growth work Security review External review for one public website
Pricing
Login Start for free
Services Web developmentFrontend, backend and integrations Development retainerCompare monthly support models Website maintenanceOngoing fixes, updates and growth work Security reviewExternal review for one public website Pricing Login

Legal

Security overview

TUNDRÄ applies proportionate safeguards for ordinary website-project data. Sensitive access values belong in the encrypted Secrets area, while the standard portal remains unsuitable for payment-card data or large volumes of regulated personal data.

Effective July 13, 2026 · Version 2026-07-13

Legal documents
Terms of serviceService scopeBilling & subscriptionsCancellation & refundsAcceptable usePrivacy noticeCookie noticeData processing addendumSeller informationSecurity

1. Current safeguards

  • Encryption in transit is used for production website and account traffic.
  • Portal account passwords are protected using one-way cryptographic controls; write-only values in Secrets use authenticated encryption at rest.
  • Access to Customer records is restricted by account, organisation and role.
  • Reasonable controls are applied to authentication attempts, sessions and uploaded files.
  • Material account and service activity may be logged for security, support and accountability.
  • Personnel access is limited according to operational need and confidentiality obligations.
  • Complete payment-card data is handled by Lava.top and is not stored in the TUNDRÄ portal.

2. Data minimisation

The most effective control is not collecting unnecessary data. Customers should provide redacted screenshots, synthetic test users and the smallest data sample needed. Passwords, private keys and API tokens must go only into the dedicated Secrets area, never task comments, email or ordinary attachments. Do not upload seed phrases, complete card data, government identifiers, health information, children’s data or full production databases under the standard Service.

3. Credentials and access

Credentials should be shared through the encrypted Secrets area, a Customer-approved password manager or a time-limited platform invitation, not task comments or email. Secret values are stored separately from task conversations and encrypted at rest. After a value is saved, the portal and its client-facing API return only the key name and update date, never the stored value. Customers can replace or delete a pair, and those actions may be audited. Customers should grant least privilege, enable multi-factor authentication where available, review access regularly and revoke it after completion. We may refuse access that is shared insecurely.

4. Production and recovery

Before material production changes, the Customer must maintain a recoverable source and data backup or authorise a task-specific backup. TUNDRÄ operational copies are not a substitute for the Customer’s business-continuity plan. Deployment, rollback, retention and recovery requirements beyond reasonable standard precautions must be stated in an Order Form.

5. Personnel and providers

Access is limited to personnel who need it for delivery or support and who are subject to confidentiality duties. We require service providers that handle personal data on our behalf to apply appropriate security and confidentiality safeguards. We review access when roles change and may log administrative actions.

6. Incident response

We investigate suspected unauthorised access, contain affected systems, preserve relevant evidence, assess scope, restore safe service and notify affected Customers or authorities where required. Under a DPA, we notify the Customer without undue delay after becoming aware of a confirmed Personal Data Breach involving Customer Personal Data and provide information reasonably available at the time.

7. Reporting a vulnerability or incident

Email support@tundraa.dev with “Security report” in the subject. Include the affected URL or account, timestamps, steps to reproduce and potential impact. Do not access other users’ data, disrupt service, use social engineering, demand payment, or publicly disclose an unresolved issue. Do not attach active malware or secrets.

8. No certification claim

This overview is not a warranty of absolute security or a claim of independent certification. Customers needing specific data residency, audit, dedicated infrastructure or contractual recovery objectives must agree them before transferring relevant data.

TUNDRÄ © 2026
Retainer guide Website maintenance Terms Privacy Security Security review Cookies Refunds Legal notice