Security Policy
Version: Oct 5, 2026
Mynewsdesk AB, headquartered in Stockholm, is a modern Saas company using third-party cloud-providers, open-source software and modern agile product development processes to be able to provide a competitive product in a fast moving landscape.
Mynewsdesk security measurements are compliant with applicable law and are following industry security standards for cloud services.
Mynewsdesk is owned by the company NHST who is governing all companies in the group with an information security policy.
Technical and organisational measures
Hosting
Mynewsdesk is hosted by Hetzner and AWS, who constantly monitor for security threats and act accordingly.
Amazon continually manages risk and undergoes recurring assessments to ensure compliance with industry standards. Amazon's data center operations have been accredited under:
- ISO 27001
- SOC 1 and SOC 2/SSAE 16/ISAE 3402 (Previously SAS 70 Type II)
- PCI Level 1
- FISMA Moderate
- Sarbanes-Oxley (SOX)
Hetzner and is certified in accordance with ISO 27001.
Location
Servers for AWS and Hetzner are located within EU.
Availability
Mynewsdesk services have a goal of being available 99.99% on a yearly basis. Our hosting partners are enabling high availability by providing automatic fail-over and avoiding single point of failures. Health status for Mynewsdesk services can be found on status.mynewsdesk.com.
Application Stack
Mynewsdesk is written in the web framework Ruby on Rails and has been tried by the open source community in terms of security. Applications are running Kubernetes using Talos Linux. Internal backend services are communicating on authenticated and encrypted channels, using industry standard encryption methods and leveraging Extended Validation(EV) supported certificate handling.
Access Control
Employees and consultants at Mynewsdesk may be granted access to production data by granularity levels. Two-factor authentication is enabled when applicable. Changes to customer’s content through the services are logged.
Backups
Mynewsdesk is performing backup of customer data. Backups of customer data are kept for 30 days for system recovery. Application logs are stored in separate systems and are retained for a longer time for information security consistency.
Automatic monitoring
Mynewsdesk makes use of automated third party services to analyze code changes for security vulnerabilities. The applications are also being pen-tested by external parties that report vulnerabilities with cvss-scoring. Libraries are being automatically scanned for security upgrades by third-party services.
Privacy By Design
Mynewsdesk is proactively working with security and how we handle personal data in our development process as set out by the Privacy by Design methodology. Our process follows check-lists for processing of personal data including using encryption or pseudonymization to prevent data breaches.
Deployment
Mynewsdesk uses automatic code-tests to ensure that new changes don’t break existing functionality. All code is also being reviewed by another person before being merged into the master code tree. On top of that we have a manual QA process for testing new functionality before it’s being released to production.
Code updates to the production environment are done on a daily basis. Each release to production carries information with traceability.
Security & Privacy Governance
Mynewsdesk have assigned Data Privacy Officers within the company that are governing technical and organisational measures on how we are processing personal data according to applicable law. Mynewsdesk has designated people that are working together with NHST to ensure compliance with NHST information security policy.
Employees, contractors, sub-processors
All devices of Mynewsdesk employees are individually password-protected and encrypted as defined in an internal IT-policy. Employees' devices can be remotely wiped by our IT-department in the event of theft or similar.
Mynewsdesk ensures that people authorised to production data have committed themselves to confidentiality. Processing of data is regulated by data processing agreements and our privacy policy.
Data breaches
Mynewsdesk has established a routine for managing personal data breaches with an escalation program to ensure that we can notify affected parties as soon as possible and that we can report about an incident within 72 hours to the data authority in Sweden (Integritetsskyddsmyndigheten).