You have the right to know where your data lives

When we build a shipping, invoicing or inventory system for a company, we are handling that company’s most critical data. That is why security is not an item added at the end of the project, but part of the design from the first day of setup.

01

Where the data lives

Your systems are hosted on Google Cloud infrastructure, in a project that belongs to you. Data is kept in a database only you can access, not in a shared pool of ours. Project ownership is set up in your name from the start; if our relationship ends, the system stays with you.

02

Who has access

Each user can only see their own work. Role- and permission-based access is defined; a user on the shipping team cannot see finance screens, and a user on the factory side cannot see head-office data. Permissions are updated together with you throughout the project.

03

What gets logged

Critical actions leave a trail: who created or changed a record, and when, is visible in the system. When a delivery was marked, or who revised a quote, is information that can be looked up later.

04

Backup and recovery

The database is backed up regularly and the restore procedure is kept as a written runbook — so in a crisis nobody has to work out “how was this done”; the steps are ready. For large data migrations, an analysis is produced beforehand and a validation report afterwards.

05

Secret management

API keys and service accounts are never written into code or the repository; they are read through encrypted secret management (Secret Manager). An automated pre-release scan checks that no secrets remain in the repository.

06

KVKK and personal data

If the system holds personal data, we decide together which fields are kept and why, in line with KVKK (Turkish Personal Data Protection Law). We don’t collect unnecessary data; access, correction and deletion requests have a counterpart in the system.

In practice

This approach is in use in the Şahika Group system today: permission-based user management, action history and a written backup procedure are part of the system.

Read the Şahika Group case

Let’s answer your questions.

Where your data will be kept, who will have access and how backups will work — we put all of it in writing before the project starts.

Get in Touch