Back to homeLegal

Security

Last updated: July 30, 2026

Security is foundational to how Ghost Con Oy builds and operates its platform. This page describes the technical and organizational measures we take to protect your data and keep the Services reliable.

Our security commitment

Ghost Con Oy treats the security of customer data as a top priority. We follow industry best practices and continuously review and improve our security posture. Our approach combines preventive controls, continuous monitoring, and a clear incident response process.

We design our systems with security in mind from the start, applying the principle of least privilege, defense in depth, and secure-by-default configurations across our infrastructure and application layers.

Data encryption

All data transmitted between your browser or application and our servers is encrypted in transit using TLS (Transport Layer Security). Data stored at rest in our databases and storage systems is encrypted using strong, industry-standard algorithms.

Passwords are never stored in plain text. We hash passwords using a one-way cryptographic function with a per-password salt, so even our engineers cannot see your password.

Access control

Access to customer data is restricted to authorized personnel who need it to perform their job duties, and is governed by the principle of least privilege. Internal access is granted through role-based permissions and is reviewed regularly.

All administrative access to production systems requires multi-factor authentication and is logged. Access is revoked promptly when an employee changes roles or leaves the company.

Infrastructure and hosting

The Hero Monday platform is hosted on reputable cloud infrastructure providers that maintain recognized security certifications, including ISO 27001 and SOC 2. Our infrastructure is deployed across multiple availability zones to provide resilience and high availability.

We apply security patches and updates to our systems promptly after they are released and tested, and we monitor for known vulnerabilities in the libraries and dependencies we use.

Application security

Our development process includes secure coding practices, code review, and regular security testing. We perform vulnerability scanning and periodic penetration testing to identify and remediate weaknesses before they can be exploited.

We separate customer data logically so that one customer cannot access another customer's data. Each account is isolated, and access to data is validated on every request.

Monitoring and incident response

We continuously monitor our systems for suspicious activity, performance anomalies, and potential security events. Alerts are reviewed by our team and escalated according to our incident response plan.

In the event of a confirmed security incident affecting customer data, we follow our incident response process to contain, investigate, and remediate the issue. We notify affected customers without undue delay, in accordance with our obligations under the GDPR and applicable law, and provide clear information about what happened and what we are doing about it.

Data backups and recovery

Customer data is backed up regularly to enable recovery in the event of data loss or system failure. Backups are encrypted and stored in geographically separate locations. We test our backup and recovery procedures to ensure we can restore service within our target recovery objectives.

Employee practices

All Hero Monday employees and contractors are subject to confidentiality obligations. We provide regular security awareness training and require staff to follow our information security policies. Background checks are conducted for roles with access to sensitive systems.

Sub-processor security

We engage sub-processors only under written agreements that require them to maintain security measures comparable to our own and to process data solely on our instructions. We review our sub-processors' security practices and certifications before engaging them and periodically thereafter.

Compliance

GDPRGDPR
ISO 27001ISO 27001
ISO 27018ISO 27018
HIPAAHIPAA

Ghost Con Oy is committed to compliance with the EU General Data Protection Regulation (GDPR) and Finnish data protection law. We support our customers' compliance obligations by providing the tools and agreements they need, including Data Processing Agreements and clear documentation of our security measures.

Responsible disclosure

We welcome responsible disclosure of potential security vulnerabilities. If you believe you have identified a security issue, please contact us at security@heromonday.fi with a detailed description. We ask that you avoid accessing or modifying customer data and that you give us reasonable time to respond before any public disclosure.

We are committed to acknowledging and addressing legitimate reports promptly and to working collaboratively with researchers who help us improve our security.

Contact

For security questions, concerns, or vulnerability reports, contact us at security@heromonday.fi. For data protection inquiries, contact privacy@heromonday.fi.