Security
Last updated: October 2, 2026
This page describes how Gadder secures gadder.no, Privat and Proff, and how to report a possible vulnerability. Business customers can request detailed security documentation and a data processing agreement.
All traffic is encrypted with HTTPS.
Our APIs require sign-in by default.
Report vulnerabilities to info@gadder.no.
1. Hosting and storage
The services run on Microsoft Azure. Databases and files are stored in Azure and encrypted at rest. All traffic between your browser and the services uses HTTPS, and browsers are instructed never to use an unencrypted connection (HSTS).
Secrets such as keys and passwords for subprocessors are kept in Azure Key Vault, not in source code.
2. Sign-in and access
Privat and Proff share one sign-in. You can sign in with email and password, Vipps or Google, and you can turn on two-factor authentication with an authenticator app.
All API endpoints require sign-in unless they are deliberately public, such as address search and calculations in the open energy plan. Access is role-based, and administrative functions require the administrator role. Sessions can be revoked, and sign-in is rate limited against repeated attempts.
3. Logging and traceability
We log security events and changes so that we can detect misuse and fix errors. Personal data such as names, email addresses, phone numbers and addresses is masked before requests are logged, and IP addresses are stored pseudonymized or as an approximate location.
How long logs are kept is described in the privacy policy.
4. Artificial intelligence
Some features use AI models, including analysis of floor plans and documents. Content is only sent when you use the feature, and we do not allow the data to be used to train the providers' general models. The providers we use are listed in the privacy policy.
5. Subprocessors
We use a limited set of subprocessors for hosting, email, payments, analytics and AI. The list and their purposes are in the privacy policy. Business customers can request a complete list including storage locations.
6. Reporting vulnerabilities
If you have found a possible vulnerability, we want to hear from you. Send a description to info@gadder.no with the subject “Security”, ideally including the steps needed to reproduce it. Machine-readable contact details are in /.well-known/security.txt.
Please do not access, change or delete other people's data, do not disrupt the service, and give us reasonable time to fix the issue before disclosing it publicly. We will confirm that we have received your report and keep you updated.
7. Security incidents
In the event of a personal data breach, we notify the Norwegian Data Protection Authority within 72 hours where required, and affected customers and users without undue delay.
8. For business customers
If your organization uses Proff, we can enter into a data processing agreement and answer supplier and security assessments. Contact us at info@gadder.no.
Questions about security?
Write to us to report a vulnerability or if you need security documentation.