Systems Security & Data Protection

Last updated: October 1, 2026 · Compliance with GDPR, ISO/IEC 27001 & PCI-DSS standards

At Tredi (Perk Drop SL), operational resilience and information security are foundational architecture components. We deploy state-of-the-art technical and organizational measures to safeguard the integrity, confidentiality, and availability of diner, merchant, and partner data.

1. Technical Measures & Defensive Architecture

End-to-End Encryption

All traffic is routed via TLS 1.3 / HTTPS with Perfect Forward Secrecy. Data at rest is encrypted with AES-256 using hardware HSM-managed keys.

Multi-Tenant Isolation & RLS

PostgreSQL database strictly enforces Row Level Security (RLS). Each merchant can only access their own sales records, redemptions, and analytics.

Secure Payments & PCI-DSS

Payment processing and subscriptions are delegated entirely to Stripe Inc., a PCI-DSS Level 1 certified provider. Tredi never stores credit card numbers or CVV on its servers.

Cryptographic Redemption Validation

Point-of-sale transactions and Tred redemptions are cryptographically signed and authenticated via ephemeral tokens and GPS geofences to prevent fraud and duplication.

2. Responsible Vulnerability Disclosure Program

We value and welcome collaboration from cybersecurity researchers. If you identify a potential vulnerability on our platform, please report it immediately following coordinated disclosure best practices.

Security reporting channel: legal@tredi.app

Please include a detailed technical description and reproduction steps (PoC), and maintain confidentiality until our engineering team deploys the appropriate mitigation.

3. Incident Response & Operational Resilience (GDPR Art. 33)

Tredi maintains formal response protocols for security incidents and operational continuity:

Statutory Notification to DPA in ≤ 72 Hours

In compliance with Article 33 of GDPR, any personal data breach will be reported to the Spanish Data Protection Agency (AEPD) within 72 hours of discovery, simultaneously applying immediate corrective actions and notifying affected individuals if high risk exists.

Continuous Backups & Recovery (PITR)

Databases operate continuous automated Point-in-Time Recovery (PITR) backups with AES-256 encryption at rest and geographical redundancy within the European Union to guarantee availability and disaster recovery.