Skip to content
andarama

Institutions

Security and data protection

What the IT department or the data protection officer usually asks before buying, answered with what is actually there.

Architecture

andarama.com runs on Cloudflare: a Worker serves the API, the Studio and the tours; the database is D1 (managed SQLite); media and tiles are stored in R2 (object storage); KV holds short-lived technical data and Durable Objects coordinate real-time editing and live guided visits. Accounts, sign-in and billing are handled by Clerk. Tour analytics are our own and cookie-free, and website analytics are done by Plausible.

Where the data lives

  • Database (D1) and media (R2): in Cloudflare data centres in Western Europe. This is the location chosen when they were created; we are working on also pinning it to the European Union jurisdiction.
  • Execution: the code runs on Cloudflare's network, in the data centre closest to the visitor.
  • KV: ephemeral technical data (read sessions, publication pointers) replicated across the network.
  • Accounts and billing: in Clerk, in the United States (email, name, session and billing details). Tours and media do not go through Clerk.
  • Website analytics: Plausible, in the European Union, with no cookies and no IP addresses.

If the institution needs everything to stay in-house, the same application can be installed on its own infrastructure (see below).

Encryption

All traffic goes over HTTPS with TLS and HSTS. Cloudflare encrypts the D1 database and R2 objects at rest. Passwords and service secrets are never stored in plain text, and API tokens are stored as a hash.

Access and authentication

On andarama.com access is managed by Clerk, with two-step verification available. Inside the application, organisations have roles (admin, editor, contributor, reader) and permissions are checked on the server on every route. A self-hosted install also offers local accounts with two-step verification (TOTP) and institutional SSO via OIDC.

Application protection

Content Security Policy (CSP) with nonces, double-token CSRF protection, rate limits, Turnstile against form abuse, sanitised SVG, Markdown and CSS, and an audit log of administrative actions. Continuous integration runs the tests and the dependency audit on every change.

Backups

D1 allows point-in-time recovery of the database (Time Travel) for the period Cloudflare offers, and the admin panel exports a full copy of the database. R2 media has no automatic versioning: that is why we recommend keeping the originals of your photographs and exporting important tours.

Auditable code

The full code is published under EUPL-1.2 on GitHub: anyone can check how data is handled. Vulnerabilities are reported privately following the repository's SECURITY.md file. More on the open source page.

Exit plan

Nothing you create gets locked in. Tours can be exported at any time as a static ZIP, a single HTML file or a PWA, which work without Andarama, and as an .andarama file. The tour.json format is documented. And the same application can be installed on the institution's infrastructure (Docker, its Cloudflare account or a desktop executable), so the day the hosted service is no longer contracted, the work carries on.

What we do not have (yet)

Andarama does not hold its own certification under Spain's National Security Framework (ENS) or ISO 27001. Cloudflare and Clerk hold their own certifications as providers. If the institution requires ENS, a self-hosted install on its infrastructure falls under its own ENS. On request we prepare the data processing agreement (article 28 of the GDPR) and a technical sheet with this information.

Do you need the documentation?

Data processing agreement, technical sheet, accessibility statement or a meeting with your IT department: ask us and we will send it over.