1. Summary
Uretyco is built around three operational commitments: customers stay in control of their data and IP, suppliers are vetted and held to objective standards, and security claims are honest. Where we have not yet completed a certification, we say so. Where a control is in design, we mark it accordingly.
2. Data protection program
Our data protection program is aligned with KVKK (Türkiye) and GDPR (European Union) requirements. The core elements are:
- A documented data inventory listing every category of personal data we process and its lawful basis.
- Data subject request workflow with a 30-day SLA, fully described in the DSR portal.
- Privacy-by-design review for new platform features that touch personal data or CAD/IP.
- Vendor risk assessment for every subprocessor, refreshed annually.
- Mandatory data protection training for all staff members at hire and each year thereafter.
3. Security controls in place
| Domain | Control | Status |
|---|---|---|
| Transport security | TLS 1.3 with strong cipher suites; HSTS preload. | In place |
| Data at rest | AES-256 encryption for CAD storage and database backups. | In place |
| Identity and access | SSO and MFA mandatory for all staff accounts; role-based access on least privilege. | In place |
| Application security | Code review for security-sensitive paths; dependency scanning on every PR. | In place |
| Customer file isolation | Per-tenant scoping enforced at the database, storage, and worker layers. | In place |
| Logging and monitoring | Structured logs to a centralised store; on-call alerting on critical signals. | In place |
| Backup and recovery | Daily backups with 35-day retention; quarterly restore drills. | In place |
| NDA with manufacturing partners | Back-to-back NDAs mirroring customer protections; scoped CAD access per Order. | In place |
4. Roadmap and what is in progress
To stay honest, we list controls that are not yet fully in place but are on our roadmap. We do not claim certifications we have not earned.
| Initiative | Target | Status |
|---|---|---|
| ISO 27001 alignment | Statement of Applicability and gap-closure | In progress |
| SOC 2 Type II readiness | Control design and observation period | Planning |
| Annual external penetration test | Web app + supplier portal scope | Planning |
| Public bug bounty program | Coordinated disclosure to start | Planning |
Until these initiatives are complete we will not display certification badges that imply they are. The honest signal is the table above.
5. Subprocessors
We engage a small number of subprocessors that are necessary to operate the platform. The list below is current at the date at the top of this page.
| Provider | Role | Region |
|---|---|---|
| Vercel | Application hosting and CDN. | EU and US (SCCs) |
| Supabase | Authentication, database, file storage. | EU |
| Email service (transactional) | Transactional email delivery. | EU |
| Payment processor | Card and bank payments. | Türkiye and EU |
| Analytics (opt-in) | Aggregated platform analytics where consented. | EU and US |
| Pexels | Editorial cover image hosting. | Global CDN |
| Manufacturing partners | Production of customer parts. | Türkiye, EU, selected APAC and Eastern Europe |
6. Manufacturing standards
Standards we apply to every Order, regardless of supplier:
- Default tolerances per ISO 2768-mK on machined metal parts; tighter values must be called out on the drawing.
- Default inspection: 100% visual + sample dimensional. Tighter inspection (FAI, CMM, full dimensional report) is opt-in and called out on the Order.
- Material Test Reports (MTR) for aerospace, medical, and regulated industry orders by default; on request for commercial orders.
- Certificate of Conformance (CoC) included on every shipment.
- Defect handling per the Sales and Manufacturing Agreement, with a 5-day inspection window.
7. Incident response
Our incident response procedure covers detection, triage, containment, eradication, recovery, and post-incident review. For incidents involving personal data, KVKK requires notification of the supervisory authority within 72 hours where there is a risk to data subjects. We aim to notify affected customers within 48 hours of confirmation, with what we know and what we still need to investigate.
8. Audits and assurance
We run quarterly internal audits of key controls (access reviews, backup restore drills, vulnerability scans). We are preparing for our first independent audit as part of the ISO 27001 alignment program. Customers running an enterprise procurement process can request a security questionnaire response and a current scan summary by emailing info@urety.co.
9. Report a vulnerability
Security researchers are welcome. Send vulnerability reports to info@urety.co. We acknowledge within 2 business days, do not pursue researchers acting in good faith under coordinated disclosure, and credit reporters in our changelog when they wish.
