Security

Security and data protection

The technical and organisational measures behind this site, described plainly.

Last updated 5 August 2026

The short version

The smallest attack surface is the one that does not exist. This site is static files: no database, no user accounts, no sessions, no server-side application code, and no third-party scripts.

Most website compromises come through a CMS plugin, an outdated dependency executing on a server, or a third-party tag. None of those are present here. What is served is HTML, CSS, one JavaScript bundle and media, generated at build time and delivered from a CDN.

In transit

The application

The data involved

There is very little, and that is deliberate.

Collected automatically
Server log entries created by the act of requesting a page — IP address, timestamp, path, status, user agent. Held by the host.
Collected from you
Only what you choose to send us by email. The lane you build in the planner stays in your browser until then.
Stored on your device
Nothing. No cookies, no local storage, no session storage — see cookie settings to verify it live.
Special category data
None is requested, and none should be sent to us through this website.

Organisational measures

If something goes wrong

A personal data breach that is likely to result in a risk to people’s rights is reported to Die Landesbeauftragte für den Datenschutz Niedersachsen within 72 hours of us becoming aware of it, as Art. 33 GDPR requires. Where the risk is high, we notify the people affected directly under Art. 34.

If you think you have found a vulnerability, please tell us before you tell anyone else — see responsible disclosure.

What this page covers

This describes the website. The security of a physical consignment — escorts, sealed handover, licensed magazines, documented chain of custody — is a different subject, dealt with in the service itself and in the terms and conditions.