Position Eleven

Security

Last reviewed 7 October 2026

Your data in transit and at rest

  • Every connection is HTTPS, and browsers are told to refuse anything else (HSTS).
  • Google access tokens are encrypted at rest. Passwords are stored only as salted hashes. Two-factor secrets and recovery codes are encrypted.
  • Card details go straight to Stripe and never reach our servers.
  • We ask Google only for read access to Analytics and the Ads access the product needs, and you choose exactly which accounts we read. Disconnecting destroys the stored token.

Who can see what

  • Every customer's data is walled off from every other customer's. That boundary is covered by automated tests that run before each release.
  • Every request that touches a customer's data is logged, including refused ones. Changes to accounts are kept in an audit trail, which is built so that it never stores passwords, tokens or other secrets.
  • Two-factor authentication is available on every account, and is required for staff accounts, which can see more than one customer.

Infrastructure

  • The application runs on a server we operate ourselves, hosted by netcup in Nuremberg, Germany. Email is sent through Mailgun's EU region.
  • Databases are backed up every night, encrypted, with a copy held off the server. Restores are rehearsed, not assumed.
  • The service is monitored around the clock, and we are alerted when anything a customer would notice stops working. Current status: app.positioneleven.com/status.
  • Dependencies are checked against published security advisories before every release.

Reporting a vulnerability

If you think you have found a security problem, email security@positioneleven.com. Please give us a reasonable chance to fix it before telling anyone else, and do not access other people's data or degrade the service while testing. We will reply, keep you informed, and credit you if you would like.

Machine-readable: /.well-known/security.txt

Related

Privacy policy, including who else processes data for us · Terms · Contact