Trust center
Security and service resilience
How Consentory protects accounts, isolates customer data, records consent events and behaves when a dependency is unavailable.
Service operator and security contact
AKSAMIT PROJECTS sp. z o.o., Warsaw, Poland, operates Consentory. Report suspected vulnerabilities or security incidents to security@consentory.io. Account and availability questions go to support@consentory.io.
Account and application controls
- Passwords are hashed with bcrypt; access and refresh sessions are revocable and refresh-token reuse is detected.
- Authentication cookies are Secure, HttpOnly, SameSite=Strict and host-only in production.
- Administrator MFA is supported, privileged routes enforce roles, and website resources are scoped to their owner.
- State-changing browser requests are checked against the allowed origin; rate limits protect authentication, scanning and public consent ingestion.
Infrastructure and data protection
- TLS is required for production public-service traffic. Database and cache network exposure must be verified in the deployment environment before production use.
- Consent evidence tokens are signed; legal HTML is sanitised; uploaded images are decoded and re-encoded before storage.
- The scanner restricts destinations to public hosts and approved ports to reduce server-side request forgery risk.
Consent record contents and retention
A consent event can contain a pseudonymous visitor identifier, decision, accepted purpose categories, event type, timestamp, configuration and widget versions, selected language, policy URL, configuration snapshot and evidence source. Consentory does not require a visitor name or email for this record.
The default retention period is 12 months. Private-beta plan targets are 30 days for Free, 12 months for Starter, 24 months for Growth and a documented custom period for Scale. The controller must select a period justified for its accountability needs and local limitation rules.
Retention, export and recovery
Consentory maintains consent evidence, technology inventories and reports for the retention period included in the customer’s plan or otherwise agreed in writing. Customers that need to preserve records beyond that period should export the relevant evidence before a downgrade, cancellation, suspension, the end of beta access or a change to the retention settings.
Customers should export evidence before downgrade, cancellation, suspension, the end of beta access or a retention change. Backup and restoration commitments are not offered during the current private beta.
Widget behaviour during failure
- If the configuration endpoint is unavailable, the widget does not treat optional purposes as granted and does not activate managed optional scripts.
- If consent recording fails, the browser choice can still control the current page, but the event is not represented as stored evidence. The integration must monitor ingestion and retest after recovery.
- Strictly necessary website functions remain the responsibility of the customer website and should not depend on an optional Consentory category.
- Customers should retain a tested rollback path, avoid duplicate CMP scripts and verify accept, reject, granular and withdrawal paths after material releases.
Incident handling and beta limitations
We investigate confirmed incidents, preserve relevant audit records, contain affected access and notify controllers without undue delay when an incident affects customer personal data. Notification content depends on verified scope and available facts.
Consentory is in private beta. Security controls and recovery procedures continue to mature; specific SLA, audit and penetration-test commitments apply only when agreed in writing.