top of page

Security Policy

For us, security is not merely a feature; it is a fundamental commitment. Below, we outline the layered security architecture we employ to protect the corporate data processed on our platform. ​

Perimeter Network Security

All traffic directed to our platforms passes through global Cloudflare DDoS, WAF (Web Application Firewall), and intelligent bot management layers before reaching our application servers. IP Masking and DDoS Protection: The actual IP addresses of our origin servers are fully masked behind the edge network. DDoS attacks targeting the servers directly are mitigated at the edge servers before they can reach our infrastructure. Proactive Threat Prevention: All incoming HTTP/HTTPS requests undergo anomaly checks; SQL injection, malicious bot activity, and data scraping attempts are proactively blocked at the network gateway. International Traffic Filtering: To maintain the highest level of data and server security, all traffic originating from outside Turkey is subject to an automated security verification process (Managed Challenge). Data Communication Security: Our platform's cybersecurity infrastructure is periodically audited by globally recognized independent authorities such as Qualys SSL Labs. It is secured with the highest "A+" rating, supported by 256-bit SSL encryption, TLS 1.2/1.3 protocols, HSTS Preload policies, and comprehensive Content Security Policy (CSP) rules. All our digital processes feature a proactive defense layer utilizing modern browser security headers (Permissions-Policy, X-Content-Type-Options, etc.). Furthermore, all SSL/TLS certificates associated with our domain names are continuously monitored using Certificate Transparency (CT) log monitoring systems to instantly detect any attempts to issue unauthorized or fraudulent certificates. Server-Level Hardening: All internal service ports on the server are completely closed to the outside world. External access requests are securely routed to the server only after being filtered through an encrypted Nginx reverse proxy and local firewall (UFW) rules.

Server and Operating System Hardening

Our server-level security is based on the "Principle of Least Privilege." Remote access to servers within our infrastructure via passwords has been completely disabled. System access is permitted only through high-bit cryptographic private key pairs (SSH Key-Only) and exclusively from devices with full-disk encryption enabled. Operating system-level firewalls expose only the necessary network ports to the outside. Any unauthorized connection attempts are automatically blocked upon detection. All system activities and authorization checks on the server are logged with the highest level of detail. All system access within our infrastructure is logged in real-time via advanced audit logs. Unauthorized access attempts or suspicious system activities are detected by our proactive security protocols. System security is continuously hardened through the "Principle of Least Privilege" and periodic security assessments.

Data and Identity Cryptography

User passwords are never stored in plain text in our databases. They are stored as one-way hashes using the industry-standard bcrypt algorithm, which offers high resistance against hardware-based brute-force attacks and supports dynamic salting. ideative employees have no access to user passwords under any circumstances. Session management at the application layer is handled via cryptographically signed JWT structures and role-based access control (RBAC). Each user can only access data within the scope of their authorization. Authentication and Session Security: System login is secured by two-factor authentication (2FA), which requires a one-time verification code sent to the user's registered email address following password validation. Access tokens for terminated sessions are immediately invalidated and cannot be reused. Passwords are subject to a strong password policy requiring specific criteria regarding length and the inclusion of letters, numbers, and special characters. Change Auditing: All data deletion and update operations performed on the platform are recorded in a central audit log—capturing user and timestamp details—and are automatically purged upon the expiration of the statutory retention period.

Physical and Hardware Infrastructure

The physical infrastructure hosting our artificial intelligence models and industrial databases is located in a Tier III certified data center in Türkiye.

Offering 99.98% availability, this infrastructure is equipped with redundant power lines, redundant climate control systems, biometric access controls, and 24/7 closed-circuit camera monitoring. All customer data is stored in Türkiye.

KVKK Compliance

ideative® fulfills its obligations under the Personal Data Protection Law No. 6698. Personal data storage and destruction processes are managed via automated systems, and destruction activities are recorded for legal evidentiary purposes. Requests from data subjects regarding data processing, deletion, or access are concluded within the statutory 30-day period, and a written response is provided. Detailed information regarding our data processing activities can be found in our Privacy Policy.

Retention Period for Personal Data

Ideative® retains personal data for the duration required by the purpose of processing, in compliance with applicable statutes of limitations and legal retention obligations. Our data retention processes are managed within the framework of a "Data Retention and Disposal Policy" optimized according to the nature of the data. Our Company promptly deletes, destroys, or anonymizes data once the purpose for processing has ceased or the legal retention periods have expired. These processes are automated through a periodic disposal schedule executed annually in January and July.

Data Backup and Disaster Recovery

As part of its business continuity measures, ideative® regularly backs up all its data. Data backups are secured using AES-256 (GPG) encryption standards and stored redundantly in a cloud location. This method guarantees data integrity and accessibility in the event of a disaster.

In the event of a system failure:

RPO (Recovery Point Objective): 24 hours

RTO (Recovery Time Objective): 8 hours

Hybrid Security Architecture and Artificial Intelligence Layers

Not all applications on our platform operate on a uniform infrastructure; each process is hosted within security layers optimized for the specific nature of the data and its processing requirements. Multi-Layered Processing: While some of our applications are hosted directly on our own hardened servers (on-premise/VPS) within our Tier III data center in Türkiye, certain AI-driven processes are handled by authorized AI solution partners that maintain end-to-end encryption and enterprise data privacy certifications (such as SOC 2 and GDPR). Data Isolation: Regardless of the hosting infrastructure, every application is isolated based on the "Zero Trust" principle. Data processed by our AI solution partners is strictly excluded from general model training; it is processed temporarily—and solely for service delivery—within isolated environments dedicated to the specific customer who owns the data. Responsibility Framework: We bear full responsibility for the privacy and security of customer data, regardless of the underlying infrastructure. All solution partners we engage are selected based on their adherence to audit processes and international certifications regarding data security that meet or exceed ideative® standards.

Shared Responsibility

ideative is directly responsible for the security of the infrastructure, servers, AI layer, and application code. The diligence exercised by our users—such as selecting strong passwords and refraining from sharing access credentials with third parties—is an integral part of our organizational security. ​​ ​

 

Information Security and Compliance

ideative® implements the technical and administrative measures outlined in this policy in accordance with the provisions of the KVKK (Personal Data Protection Law) and relevant legislation. The content of this policy is periodically updated to reflect changing legal regulations and technological advancements. System backups and logs are protected against cyberattacks using cryptographic methods. ​​ ​
 

Vulnerability Reporting

Our infrastructure undergoes continuous testing and updates.

You may contact our security team directly regarding any potential vulnerabilities or technical inquiries at hello@ideative.com.tr.

+90 532 552 9461

hello@ideative.com.tr

© 2026 by ideative®

ssl, güvenilir alışveriş
kredi-kart
BDES-5287_ProtectedByCloudflareBadge_web_badges_1.png
bottom of page