Netlier
FeaturesFree ScanPricingAboutContact
Sign inGet Started
Netlier

Comprehensive IT security assessment and reporting platform.

Product

  • Features
  • Free Scan
  • Pricing
  • Integrations
  • Changelog

Company

  • About
  • Blog
  • Careers
  • Contact

Legal

  • Privacy Policy
  • Terms of Service
  • Security

© 2026 Netlier. All rights reserved.

TwitterGitHubLinkedIn

Security

Security at Netlier

We build security tools. We take our own security seriously.

Infrastructure

  • Hosted on hardened Ubuntu servers in Europe
  • All data encrypted at rest (AES-256-GCM) and in transit (TLS 1.2+)
  • Database backups daily, verified weekly
  • Docker container isolation between services
  • No shared hosting, no multi-tenant infrastructure compromises

Application Security

  • Input validation on all endpoints (Zod schema validation)
  • Rate limiting on authentication, API, and scan endpoints
  • CSRF protection on all state-changing operations
  • Content Security Policy, HSTS, X-Frame-Options, and other security headers
  • Tamper-proof audit logging with SHA-256 hash chain
  • Session management with secure, HttpOnly cookies

Access Control

  • Role-based access control (RBAC)
  • Organization-level data isolation
  • API key scoping with granular permissions
  • Scope enforcement on all penetration testing operations

Monitoring

  • Fail2ban intrusion prevention (8 active jails)
  • Real-time security event monitoring
  • Automated alerting on suspicious activity
  • UFW firewall with deny-all-except policy

Compliance

  • GDPR-compliant data handling
  • Data Processing Agreements available upon request
  • Right to access, rectify, and delete personal data
  • Data retention policies enforced automatically
  • Regular security reviews and hardening

Responsible Disclosure

  • Found a security issue? We'd love to hear from you.
  • Email: security@netlier.se
  • We will acknowledge reports within 48 hours
  • We will not take legal action against good-faith security researchers
  • We ask that you give us reasonable time to fix issues before disclosure

Questions about our security practices?

Get in Touch