Safeguard
Tag

gdpr

Safeguard articles tagged "gdpr" — guides, analysis, and best practices for software supply chain and application security.

15 articles

Data Security

Soft-Deleted Records Are Still Reachable

A soft delete sets a flag and leaves the row in place, which means every single query, export, search index, and cache that touches that table has to remember to exclude it. One that does not is a path where a user's deletion was never actually honored.

Sep 18, 20267 min read
Regulatory Compliance

Deleting a User Is Harder Than You Told the Customer

The row is soft deleted, a replica has it, the search index has it, last night's backup has it, the warehouse has a copy with different keys, and two vendors you forwarded it to still hold it.

Sep 18, 20266 min read
Incident Analysis

A Vendor Just Told You They Were Breached

The notification is vague, late, and does not say whether you are affected. It starts several clocks, and one of them may be a 72-hour regulatory deadline that runs from when you became aware, not when their investigation finishes.

Sep 18, 20266 min read
Regulatory Compliance

Watch Your Own Session Replay and Read Every Field

The recording is a reconstruction of the rendered page, so anything that reached the browser is a candidate, not just what the user typed. Masking covers the fields somebody remembered to cover.

Sep 18, 20266 min read
Application Security

The Export Button Is the Shortest Path From Account to Your Data on a Laptop

Every other endpoint is paginated. Export deliberately is not. It ships as a feature request, reuses the read permission, and is almost never reviewed as a data egress channel.

Sep 18, 20266 min read
Regulatory Compliance

Your Subprocessor List Is Out of Date and That Is a Contract Problem

It was written for your first enterprise contract, it has three entries, and since then you added error tracking, support tooling, analytics and a model provider your product calls on every request.

Sep 17, 20266 min read
Regulatory Compliance

Your Staging Environment Has Production Data In It

Nobody decides to put customer data in staging. It arrives through a restore for realistic testing, a debugging export, an analytics pipeline, a laptop dump. The copies inherit none of production's controls and never expire.

Sep 17, 20266 min read
FAQ

Data Residency and Security: FAQ

Where your data lives, what actually leaves your boundary, region pinning, customer-held keys, and how residency differs from sovereignty in a security platform.

Jul 8, 20265 min read
Compliance

GDPR for software developers: privacy by design in practice

GDPR is not just a legal team's problem. Data protection by design, security of processing, and processor due diligence all translate into code, dependencies, and architecture. Here is the developer's view.

Jul 2, 20266 min read
Compliance

Application Security Compliance overview (PCI DSS, HIPAA,...

PCI DSS 4.0, GDPR, FedRAMP, SOC 2, ISO 27001, NIST 800-53, and DORA now demand application-layer evidence. Here is what each requires and where scanner-only tools fall short.

Jun 19, 20268 min read
Compliance

Cloud Data Compliance: A Practical Guide to Getting It Right

Cloud data compliance is the practice of meeting legal and contractual rules for how data is stored, processed, and protected in cloud environments. Here is how to make it real.

May 21, 20266 min read
Data Breach

Odido Telecom Breach: 6.2M Dutch Customers, Salesforce, and No Compensation (May 2026)

Odido, the Netherlands' largest mobile operator, exposed 6.2 million customers' data, including IBANs and ID details, via a vishing-driven Salesforce intrusion. In May 2026 the company ruled out compensation as mass claims mounted.

May 12, 202610 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.