Analyse Games logoAnalyseGames
Pricing
Sign inGet started
Legal

Security

How we protect accounts and data, and how to report a vulnerability.

Last updated September 15, 2026

On this page
  1. Where data lives
  2. Protecting data
  3. Protecting accounts
  4. Building and running the Service
  5. Reporting a vulnerability
  6. Questions

Your games trust us with data about their players, so security is part of how Analyse Games is built, not an add-on. This page summarises how we protect accounts and data, and how to report a vulnerability. The contractual commitments for customer data are in Annex II of our Data Processing Addendum.

Where data lives

  • Our servers and databases run in the European Union, on Hetzner, in data centres in Nuremberg and Falkenstein (Germany) and Helsinki (Finland).
  • Databases are replicated across several servers and reachable only over a private network, with TLS between services.
  • Service providers that handle data for us are listed on Subprocessors.

Protecting data

  • In transit: everything uses HTTPS with modern TLS. analyse.net sends HTTP Strict Transport Security, so browsers only connect securely.
  • Secrets at rest: store credentials, webhook secrets, Discord webhook URLs and two-factor secrets are encrypted with AES-256-GCM.
  • Hashes, not tokens: passwords are hashed with Argon2. Session tokens, ingest keys, MCP tokens and OAuth codes are stored only as hashes, so a database copy doesn't reveal them.
  • Player IP addresses are used only to look up a country when a player joins, and are never stored.
  • Separation: every record is tied to a game or studio, and every query checks what the requesting person or token is allowed to see.

Protecting accounts

  • Two-factor authentication with an authenticator app, recovery codes, or passkeys.
  • Sign-in attempts are rate limited to slow down password guessing.
  • You can see every active session with its browser, IP address and last activity, and sign out any of them.
  • Team roles (owner, admin, analyst, creator) and per-game access keep people to what they need.
  • Ingest keys can only send data for one game or studio. They can't read anything.
  • MCP apps only get read-only tools for the games you approve, and can be revoked at any time.

Building and running the Service

  • Every API validates its input, and the web app sends security headers that stop it being framed or sniffed.
  • Changes are reviewed before release, and dependencies are kept up to date.
  • Access to production is limited to the founders, with SSH keys and two-factor authentication.
  • Databases are replicated across data centres and backed up every 6 hours. Backups are kept for 3 months.
  • If a personal data breach affects your data, we notify you within 48 hours of becoming aware of it, as the DPA sets out.

Reporting a vulnerability

If you believe you have found a security vulnerability in Analyse Games, please tell us. We appreciate the work of security researchers and will not take legal action against research carried out in good faith under this policy.

How to report: email [email protected] with a description of the issue, the steps to reproduce it, and its impact. Please don't include real player data in your report.

What we ask:

  • Only test against your own account and games. Don't access, change or delete other customers' data. If you reach data that isn't yours, stop and tell us.
  • Don't run denial of service tests, spam, social engineering or physical attacks, and don't degrade the Service for others.
  • Give us reasonable time to fix the issue before telling anyone else, normally 90 days.
  • Act within the law.

What we do:

  • Confirm we received your report within [3] working days.
  • Keep you updated while we investigate and fix it.
  • Credit you publicly when it's fixed, if you'd like.

Out of scope: reports from automated scanners without a demonstrated impact, missing best-practice headers without an exploit, clickjacking on pages without sensitive actions, rate limits on non-sensitive endpoints, and issues in third-party services we don't control.

Questions

Security questions from customers, including questionnaires, go to [email protected]. Privacy questions go to [email protected].

Other legal pages

  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • Data Processing Addendum
  • Subprocessors
  • Refunds and Withdrawal
  • AI and Your Data
  • Accessibility Statement
  • Imprint
Breukers Willem Albertus E.E.Valaoritou 1, TK 10671 Athens, Greece
GEMI
186520701000
VAT
802973201
Tax office
KEFODE Attikis
Product
FeaturesPricingDocsDownloadsChangelog
Legal
Terms of ServicePrivacy PolicyCookie PolicyRefund PolicyImprintAccessibility
Data protection
Processing AgreementSubprocessorsAI and your dataSecurityContact[email protected]
Tax, consumer rights and data protection

VATPrices exclude VAT. It is charged at your local rate on consumer sales in the EU. Reverse charge applies to VAT-registered businesses outside Greece.

Right of withdrawalConsumers in the EU can withdraw within 14 days of buying a plan. If you asked for it to start straight away, you only pay for the days you used.

Your dataWe are controller for your account and processor for the player data you send us. The Privacy Policy sets out your GDPR rights, our legal bases and retention periods; the DPA and Subprocessors list cover processing on your behalf.

Where and whoStored in the EU. Reach us at [email protected], or complain to the Hellenic Data Protection Authority.

© 2026 Breukers Willem Albertus E.E., trading as VertCode Development · Analyse GamesData stored in the EU