Security at Feierfunk
Feierfunk uses technical and organisational measures intended to be appropriate to the risk of the data processed. These include encrypted HTTPS connections, secure session cookies, CSRF protection, server-side access controls, prepared SQL statements, output encoding against XSS, upload validation, restricted file types, login rate limiting, security headers, protected configuration directories and regular backups at hosting level.
Passwords and accounts
Passwords are not stored in plaintext but are processed using a dedicated password hashing method. Users should use unique passwords and not share credentials. Administrator accounts must be especially protected and the initial password must be replaced immediately after commissioning.
API and calendar access
API tokens are stored server-side only as hashes and the plaintext is shown only once when created. Private calendar feeds use long random access tokens that the provider can regenerate at any time and thereby revoke.
Security reports
Please send vulnerability reports confidentially to info@djkd-peine.de . Please do not publish third-party personal data and do not perform tests that alter data, disrupt services or affect other people's accounts.
Data protection incidents
Feierfunk documents data protection and security incidents and assesses required follow-up measures. Where the legal requirements are met, competent supervisory authorities and affected persons will be informed within the statutory deadlines.