Application and database in Frankfurt, Germany. No data leaves the EU in normal operation. Backups are kept by the database provider in the same region.
Operator-supplied credentials (machine cloud, delivery platform tokens) are encrypted with AES-256-GCM before they touch the database; the key lives in the hosting environment, not in the database. They are shown masked in the dashboard and can be rotated or deleted at any time.
Incoming webhooks are verified: delivery-platform calls by HMAC-SHA256 signature, machine-cloud calls by a per-operator secret header. Unverified calls are rejected and logged.
The courier page needs no login. It accepts only an order code that matches an open order; wrong codes are slowed down and logged. A door unlock is tied to one order and closes after the machine's own timeout.
Every API call, webhook and state change is logged with timing and status so operators can see exactly what happened. Secrets are masked in logs. Logs older than 7 days are deleted automatically unless an operator keeps them.
Email hello@norderaworks.com with "security" in the subject. We acknowledge within two working days and do not pursue good-faith researchers.