SECURITY
Security at HOLMI
HOLMI is built according to the principle of Least Privilege and with several independent layers of protection.
Current pre-launch measures
- HTTPS/TLS and HSTS on production domains;
- restrictive browser security headers;
- server-side validation of all pre-registration inputs;
- origin allowlist, payload limits, honeypot and rate limiting;
- no public SELECT, UPDATE or DELETE permissions on tables containing personal data;
- Supabase Row Level Security (RLS);
- admin access only via Supabase Auth;
- mandatory MFA for HOLMI Control;
- role and admin allowlist;
- audit/change history in the CRM;
- no service-role or payment secrets in browser code.
Before payment launch
- PSP/TWINT sandbox and webhook signature verification;
- idempotent payment and refund processing;
- separation of authorization, capture and refund;
- backup and restore tests;
- incident response runbook;
- regular permissions and role review;
- dependency and vulnerability management;
- monitoring, alerting and error tracking;
- fraud controls for promotions and orders;
- reconciliation between orders, payments, refunds and statements.
Responsible security reporting
Reports of potential security issues can be sent confidentially to security@holmi.ch . Please do not publicly disclose security vulnerabilities or access or modify other people's data.
No promise of absolute security
No IT system can guarantee complete security. HOLMI adapts its safeguards based on risk as functions, threats and technology evolve.
Last updated: 16 September 2026