gadder

Security

Last updated: October 2, 2026

This page describes how Gadder secures gadder.no, Privat and Proff, and how to report a possible vulnerability. Business customers can request detailed security documentation and a data processing agreement.

All traffic is encrypted with HTTPS.

Our APIs require sign-in by default.

Report vulnerabilities to info@gadder.no.

1. Hosting and storage

The services run on Microsoft Azure. Databases and files are stored in Azure and encrypted at rest. All traffic between your browser and the services uses HTTPS, and browsers are instructed never to use an unencrypted connection (HSTS).

Secrets such as keys and passwords for subprocessors are kept in Azure Key Vault, not in source code.

2. Sign-in and access

Privat and Proff share one sign-in. You can sign in with email and password, Vipps or Google, and you can turn on two-factor authentication with an authenticator app.

All API endpoints require sign-in unless they are deliberately public, such as address search and calculations in the open energy plan. Access is role-based, and administrative functions require the administrator role. Sessions can be revoked, and sign-in is rate limited against repeated attempts.

3. Logging and traceability

We log security events and changes so that we can detect misuse and fix errors. Personal data such as names, email addresses, phone numbers and addresses is masked before requests are logged, and IP addresses are stored pseudonymized or as an approximate location.

How long logs are kept is described in the privacy policy.

4. Artificial intelligence

Some features use AI models, including analysis of floor plans and documents. Content is only sent when you use the feature, and we do not allow the data to be used to train the providers' general models. The providers we use are listed in the privacy policy.

5. Subprocessors

We use a limited set of subprocessors for hosting, email, payments, analytics and AI. The list and their purposes are in the privacy policy. Business customers can request a complete list including storage locations.

6. Reporting vulnerabilities

If you have found a possible vulnerability, we want to hear from you. Send a description to info@gadder.no with the subject “Security”, ideally including the steps needed to reproduce it. Machine-readable contact details are in /.well-known/security.txt.

Please do not access, change or delete other people's data, do not disrupt the service, and give us reasonable time to fix the issue before disclosing it publicly. We will confirm that we have received your report and keep you updated.

7. Security incidents

In the event of a personal data breach, we notify the Norwegian Data Protection Authority within 72 hours where required, and affected customers and users without undue delay.

8. For business customers

If your organization uses Proff, we can enter into a data processing agreement and answer supplier and security assessments. Contact us at info@gadder.no.

Questions about security?

Write to us to report a vulnerability or if you need security documentation.

Gadder AS

Org. no. 933 335 933

Universitetsveien 15, 4630 Kristiansand S

info@gadder.no