Security Policy

Version: Oct 5, 2026

Mynewsdesk AB, headquartered in Stockholm, is a modern Saas company using third-party cloud-providers, open-source software and modern agile product development processes to be able to provide a competitive product in a fast moving landscape.

Mynewsdesk security measurements are compliant with applicable law and are following industry security standards for cloud services.

Mynewsdesk is owned by the company NHST who is governing all companies in the group with an information security policy.

Technical and organisational measures

Hosting

Mynewsdesk is hosted by Hetzner and AWS, who constantly monitor for security threats and act accordingly.

Amazon continually manages risk and undergoes recurring assessments to ensure compliance with industry standards. Amazon's data center operations have been accredited under:

  • ISO 27001
  • SOC 1 and SOC 2/SSAE 16/ISAE 3402 (Previously SAS 70 Type II)
  • PCI Level 1
  • FISMA Moderate
  • Sarbanes-Oxley (SOX)

Hetzner and is certified in accordance with ISO 27001.

Location

Servers for AWS and Hetzner are located within EU.

Availability

Mynewsdesk services have a goal of being available 99.99% on a yearly basis. Our hosting partners are enabling high availability by providing automatic fail-over and avoiding single point of failures. Health status for Mynewsdesk services can be found on status.mynewsdesk.com.

Application Stack

Mynewsdesk is written in the web framework Ruby on Rails and has been tried by the open source community in terms of security. Applications are running Kubernetes using Talos Linux. Internal backend services are communicating on authenticated and encrypted channels, using industry standard encryption methods and leveraging Extended Validation(EV) supported certificate handling.

Access Control

Employees and consultants at Mynewsdesk may be granted access to production data by granularity levels. Two-factor authentication is enabled when applicable. Changes to customer’s content through the services are logged.

Backups

Mynewsdesk is performing backup of customer data. Backups of customer data are kept for 30 days for system recovery. Application logs are stored in separate systems and are retained for a longer time for information security consistency.

Automatic monitoring

Mynewsdesk makes use of automated third party services to analyze code changes for security vulnerabilities. The applications are also being pen-tested by external parties that report vulnerabilities with cvss-scoring. Libraries are being automatically scanned for security upgrades by third-party services.

Privacy By Design

Mynewsdesk is proactively working with security and how we handle personal data in our development process as set out by the Privacy by Design methodology. Our process follows check-lists for processing of personal data including using encryption or pseudonymization to prevent data breaches.

Deployment

Mynewsdesk uses automatic code-tests to ensure that new changes don’t break existing functionality. All code is also being reviewed by another person before being merged into the master code tree. On top of that we have a manual QA process for testing new functionality before it’s being released to production.

Code updates to the production environment are done on a daily basis. Each release to production carries information with traceability.

Security & Privacy Governance

Mynewsdesk have assigned Data Privacy Officers within the company that are governing technical and organisational measures on how we are processing personal data according to applicable law. Mynewsdesk has designated people that are working together with NHST to ensure compliance with NHST information security policy.

Employees, contractors, sub-processors

All devices of Mynewsdesk employees are individually password-protected and encrypted as defined in an internal IT-policy. Employees' devices can be remotely wiped by our IT-department in the event of theft or similar.

Mynewsdesk ensures that people authorised to production data have committed themselves to confidentiality. Processing of data is regulated by data processing agreements and our privacy policy.

Data breaches

Mynewsdesk has established a routine for managing personal data breaches with an escalation program to ensure that we can notify affected parties as soon as possible and that we can report about an incident within 72 hours to the data authority in Sweden (Integritetsskyddsmyndigheten).