Security
At Zapfla, security takes priority over convenience. An excerpt of our measures:
- Encrypted connections only (HTTPS/TLS) — no fallback.
- Hosting in Germany, processing under GDPR.
- Calibration-law compliant, signed meter values — checked automatically on the server.
- Strict data separation: every organization in its own data space.
- Credentials and tokens stored encrypted, never in plaintext.
- Regular updates and security audits.
Found a vulnerability?
We welcome responsible disclosure. Please report security issues confidentially to security@zapfla.de and give us reasonable time to fix them before going public.
[Placeholder — please set up/confirm the security contact.]