Systems Security & Data Protection
Last updated: October 1, 2026 · Compliance with GDPR, ISO/IEC 27001 & PCI-DSS standards
At Tredi (Perk Drop SL), operational resilience and information security are foundational architecture components. We deploy state-of-the-art technical and organizational measures to safeguard the integrity, confidentiality, and availability of diner, merchant, and partner data.
1. Technical Measures & Defensive Architecture
End-to-End Encryption
All traffic is routed via TLS 1.3 / HTTPS with Perfect Forward Secrecy. Data at rest is encrypted with AES-256 using hardware HSM-managed keys.
Multi-Tenant Isolation & RLS
PostgreSQL database strictly enforces Row Level Security (RLS). Each merchant can only access their own sales records, redemptions, and analytics.
Secure Payments & PCI-DSS
Payment processing and subscriptions are delegated entirely to Stripe Inc., a PCI-DSS Level 1 certified provider. Tredi never stores credit card numbers or CVV on its servers.
Cryptographic Redemption Validation
Point-of-sale transactions and Tred redemptions are cryptographically signed and authenticated via ephemeral tokens and GPS geofences to prevent fraud and duplication.
2. Responsible Vulnerability Disclosure Program
We value and welcome collaboration from cybersecurity researchers. If you identify a potential vulnerability on our platform, please report it immediately following coordinated disclosure best practices.
Security reporting channel: legal@tredi.app
Please include a detailed technical description and reproduction steps (PoC), and maintain confidentiality until our engineering team deploys the appropriate mitigation.
3. Incident Response & Operational Resilience (GDPR Art. 33)
Tredi maintains formal response protocols for security incidents and operational continuity:
Statutory Notification to DPA in ≤ 72 Hours
In compliance with Article 33 of GDPR, any personal data breach will be reported to the Spanish Data Protection Agency (AEPD) within 72 hours of discovery, simultaneously applying immediate corrective actions and notifying affected individuals if high risk exists.
Continuous Backups & Recovery (PITR)
Databases operate continuous automated Point-in-Time Recovery (PITR) backups with AES-256 encryption at rest and geographical redundancy within the European Union to guarantee availability and disaster recovery.